CVE-2025-29460 Details
Description
An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Add Mycode function. NOTE: the Supplier disputes this because of the allowed actions of Board administrators and because of SSRF mitigation.
A server-side request forgery (SSRF) vulnerability has been identified in MyBB version 1.8.38. This issue allows remote attackers to access sensitive information by exploiting the Add Mycode function. The vulnerability arises from improper handling of requests to private hosts and IP addresses, which could be manipulated to disclose confidential data.
MyBB board administrators are advised to update their configuration files to limit access to private hosts and IP addresses. This can be done by adding disallowed remote addresses and hosts to the MyBB configuration file, which supports wildcards and CIDR notation. Instructions for this can be found in the MyBB documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 18, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| mybb mybb | 1.8.38 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 25, 2025 | Initial Analysis | [email protected] |
| Apr 23, 2025 | CVE Modified | [email protected] |
| Apr 18, 2025 | CVE Modified | CISA-ADP |
| Apr 17, 2025 | New CVE Received | [email protected] |