Description
MyBB 1.8.32 contains a chained vulnerability that allows authenticated administrators to bypass avatar upload restrictions and execute arbitrary code. Attackers can modify upload path settings, upload a malicious PHP-embedded image file, and execute commands through the language configuration editing interface.
Problem types
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
Credits
lUc1f3r11
References
www.cve.org/CVERecord?id=CVE-2022-45867
www.exploit-db.com/exploits/51213 (ExploitDB-51213)
mybb.com/ (Official MyBB Vendor Homepage)
fdlucifer.github.io/2023/01/17/mybb1-8-32-LFI-RCE/ (Researcher Disclosure)
www.vulncheck.com/...e-execution-via-chained-vulnerabilities (VulnCheck Advisory: MyBB 1.8.32 Authenticated Remote Code Execution via Chained Vulnerabilities)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.