CVE-2023-53979

MyBB 1.8.32 contains a chained vulnerability that allows authenticated administrators to bypass avatar upload restrictions and execute arbitrary code. Attackers can modify upload path settings, upload a malicious PHP-embedded image file, and execute commands through the language configuration editing interface.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mybb:mybb:1.8.32:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-12-22 22:16

Updated : 2025-12-27 19:15


NVD link : CVE-2023-53979

Mitre link : CVE-2023-53979

CVE.ORG link : CVE-2023-53979


JSON object : View

Products Affected

mybb

  • mybb
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')