6.8
CVSSv2

CVE-2021-27890

Published: 15/03/2021 Updated: 21/09/2021
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL Injection vulnerablity in MyBB prior to 1.8.26 via theme properties included in theme XML files.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mybb mybb

Exploits

MyBB version 1825 chain remote command execution exploit that leverages cross site scripting and SQL injection vulnerabilities ...

Github Repositories

Mybb associate CVE-2021-27890 & CVE-2021-27889 to RCE poc

Mybb-XSS_SQL_RCE-POC Mybb associate CVE-2021-27890 & CVE-2021-27889 to RCE poc Before Use: There are two files here: 1js and attack_listenpy You should modify these two file: 1js: modify the mybb forum url and attack url: var bashurl = '19216892164/mybb/mybb-mybb_1825' #mybb forum url var attack_url = '19216892165:8080/attack_succ