Vulnerability record · CVE-2022-24734 · published 9 March 2022
CVE-2022-24734: MyBB Admin CP settings module type validation flaw enables RCE
Mybb · Mybb
MyBB's Admin CP Settings management module fails to validate setting types on insertion and update, allowing a setting of type `php` containing PHP code to be stored. That code executes on Change Settings pages, yielding remote code execution. The flaw affects MyBB versions before 1.8.30 and requires Admin CP access with the `Can manage settings?` permission.
Description
MyBB is a free and open source forum software. In affected versions the Admin CP's Settings management module does not validate setting types correctly on insertion and update, making it possible to add settings of supported type `php` with PHP code, executed on on _Change Settings_ pages. This results in a Remote Code Execution (RCE) vulnerability. The vulnerable module requires Admin CP access with the `Can manage settings?` permission. MyBB's Settings module, which allows administrators to add, edit, and delete non-default settings, stores setting data in an options code string ($options_code; mybb_settings.optionscode database column) that identifies the setting type and its options, separated by a new line character (\n). In MyBB 1.2.0, support for setting type php was added, for which the remaining part of the options code is PHP code executed on Change Settings pages (reserved for plugins and internal use). MyBB 1.8.30 resolves this issue. There are no known workarounds.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw gives authenticated administrators code execution, public exploit code exists, and EPSS is very high, though exploitation requires prior Admin CP access with a specific permission.
What it is
MyBB's Admin CP Settings management module fails to validate setting types on insertion and update, allowing a setting of type `php` containing PHP code to be stored. That code executes on Change Settings pages, yielding remote code execution. The flaw affects MyBB versions before 1.8.30 and requires Admin CP access with the `Can manage settings?` permission.
Impact
An attacker with the required admin permission gains arbitrary PHP code execution on the forum server, leading to full compromise of the web application and its data. The CVSS vector rates confidentiality, integrity and availability impact as high.
Attack surface
Reached over the network through the Admin CP Settings management module; the attacker must already hold Admin CP access with the `Can manage settings?` permission, and no user interaction is required. The CVSS vector is AV:N/AC:L/PR:H/UI:N.
Exploitation
Public exploit code is referenced by Packet Storm advisories, and EPSS is 0.77827 (99.5th percentile), indicating high predicted exploitation activity. The CVE is not listed in CISA KEV, so no confirmed in-the-wild exploitation is recorded here.
What to do
- Upgrade MyBB to 1.8.30 or later, which resolves the issue.
- Restrict Admin CP access and the `Can manage settings?` permission to the smallest possible set of trusted accounts.
- Audit existing settings for unexpected `php` type entries or injected code in the optionscode column.
- Monitor and alert on changes to MyBB settings, especially additions or edits of non-default settings.
- Apply the vendor patch commit and advisory guidance; the record states there are no known workarounds.
Detection
- Review the mybb_settings.optionscode column for settings of type `php` or unexpected PHP code.
- Monitor Admin CP audit or access logs for settings creation and update actions by unusual accounts.
- Hunt for unexpected PHP execution or file changes on the forum host correlated with Change Settings page access.
- Alert on administrative logins or permission changes involving the `Can manage settings?` capability.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-24734 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-24734), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.