Show plain JSON{"id": "CVE-2021-43281", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 6.5, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P", "authentication": "SINGLE", "integrityImpact": "PARTIAL", "accessComplexity": "LOW", "availabilityImpact": "PARTIAL", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 6.4, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 8.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 7.2, "attackVector": "NETWORK", "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "HIGH", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 1.2}]}, "published": "2021-11-04T18:15:08.797", "references": [{"url": "https://github.com/mybb/mybb/security/advisories/GHSA-8gxx-vmr9-h39p", "tags": ["Patch", "Release Notes", "Third Party Advisory"], "source": "cve@mitre.org"}, {"url": "https://github.com/mybb/mybb/security/advisories/GHSA-8gxx-vmr9-h39p", "tags": ["Patch", "Release Notes", "Third Party Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-94"}]}], "descriptions": [{"lang": "en", "value": "MyBB before 1.8.29 allows Remote Code Injection by an admin with the \"Can manage settings?\" permission. The Admin CP's Settings management module does not validate setting types correctly on insertion and update, making it possible to add settings of supported type \"php\" with PHP code, executed on Change Settings pages."}, {"lang": "es", "value": "MyBB versiones anteriores a 1.8.29, permite una Inyecci\u00f3n de C\u00f3digo Remota por parte de un administrador con el permiso \"Can manage settings?\". El m\u00f3dulo de administraci\u00f3n de configuraciones del CP del Administrador no comprueba correctamente los tipos de configuraciones al insertarlas y actualizarlas, haciendo posible a\u00f1adir configuraciones del tipo \"php\" con c\u00f3digo PHP, ejecutado en las p\u00e1ginas de cambio de configuraciones"}], "lastModified": "2024-11-21T06:28:59.587", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:mybb:mybb:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F65391CA-449D-44EE-8A72-C9906C5A4A6F", "versionEndExcluding": "1.8.29", "versionStartIncluding": "1.2.0"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}