CVE-2022-24734 PoC

May 8, 2022 ยท View on GitHub

An RCE can be obtained on MyBB's Admin CP in Configuration -> Add New Setting. The user must have a rights to add or update setting. This is tested on MyBB 1.8.29.

CVE gif

Sources:

  • https://github.com/mybb/mybb/
  • https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24734