CVE-2025-29459

CVSS 3.1 Score 7.6 of 10 (high)

Details

Published Apr 17, 2025
Updated: Apr 23, 2025
CWE ID 918

Summary

CVE-2025-29459 is a vulnerability affecting MyBB version 1.8.38. It enables a remote attacker to extract sensitive information through the Mail function. The specifics of the exploit involve manipulating the function's parameters, potentially leading to information disclosure. However, it's important to note that the vulnerability's validity is disputed by the supplier. They argue that designated Board administrators possess sufficient permissions and that the SSRF (Server-Side Request Forgery) mitigation is in place to prevent such attacks. Yet, until a definitive resolution is reached, it is crucial for MyBB users running version 1.8.38 to apply the available patch or upgrade to a more secure version.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share