Vulnerability record · CVE-2024-23335 · published 1 May 2024
CVE-2024-23335: Mybb improper input validation vulnerability
Mybb · Mybb
MyBB is a free and open source forum software. The backup management module of the Admin CP may accept `.htaccess` as the name of the backup file to be deleted, which may expose the stored backup files over HTTP on Apache servers. MyBB 1.8.38 resolves this issue. Users are advised to upgrade. There are no known workarounds for this vulnerability
Description
MyBB is a free and open source forum software. The backup management module of the Admin CP may accept `.htaccess` as the name of the backup file to be deleted, which may expose the stored backup files over HTTP on Apache servers. MyBB 1.8.38 resolves this issue. Users are advised to upgrade. There are no known workarounds for this vulnerability
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/mybb/mybb/commit/450259e501b94c9d483efb167cb2bf875605e111.patch | Patch |
| https://github.com/mybb/mybb/security/advisories/GHSA-94xr-g4ww-j47r | Vendor Advisory |
| https://mybb.com/versions/1.8.38 | ProductRelease Notes |
| https://github.com/mybb/mybb/commit/450259e501b94c9d483efb167cb2bf875605e111.patch | Patch |
| https://github.com/mybb/mybb/security/advisories/GHSA-94xr-g4ww-j47r | Vendor Advisory |
| https://mybb.com/versions/1.8.38 | ProductRelease Notes |
Track CVE-2024-23335 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-23335), CISA KEV, FIRST EPSS (scores of 2026-10-05). This page is refreshed as NVD updates the record.