6.5
CVSSv3

CVE-2018-11502

Published: 24/08/2018 Updated: 31/10/2018
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 585
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

An issue exists in the Moderator Log Notes plugin 1.1 for MyBB. It allows moderators to save notes and display them in a list in the modCP. An attacker can remotely delete all mod notes and mod note logs in the modCP and ACP via CSRF.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

moderator log notes project moderator log notes 1.1

Exploits

# Exploit Title: MyBB Moderator Log Notes Plugin 11 - Cross-Site Request Forgery # Date: 2018-05-17 # Author: 0xB9 # Twitter: @0xB9Sec # Software Link: communitymybbcom/modsphp?action=view&pid=1105 # Version: 11 # Tested on: Ubuntu 1804 # 1 Description: # The plugin allows moderators to save notes and display them in a list in t ...