Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
MyBB (aka MyBulletinBoard) before 1.4.12 does not properly restrict uid values for group join requests, which allows remote attackers to cause a denial of service (resource consumption) by using guest access to submit join request forms for moderated groups, related to usercp.php and managegroup.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
MyBB拒绝服务漏洞
Vulnerability Description
MyBB(又名MyBulletinBoard)是MyBB团队开发的一套用PHP和MySQL开发的免费且基于Web的论坛软件。该软件具有简单易用、支持多国语言、可扩展等特点。 MyBB(又名MyBulletinBoard)1.4.12之前版本对加入请求组的uid值没有经过正确的限制。远程攻击者可以通过使用客户访问来为moderated组提交加入请求表单,从而导致拒绝服务(资源消耗)。
CVSS Information
N/A
Vulnerability Type
N/A