Security Advisory

CVE-2018-11502

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2018-08-24 21:00:00
Last updated 2024-08-05 08:10:14
Assigner mitre
State PUBLISHED

Description

An issue was discovered in the Moderator Log Notes plugin 1.1 for MyBB. It allows moderators to save notes and display them in a list in the modCP. An attacker can remotely delete all mod notes and mod note logs in the modCP and ACP via CSRF.