Back
CVE-2015-8974
CRITICAL
SQL injection vulnerability in the Group Promotions module in the admin control panel in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Published: Jan 31, 2017
Modified: Jun 17, 2026
CWE-89
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
CHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected Products (8)
| Vendor | Product | Version |
|---|---|---|
| mybb | merge_system | * |
| mybb | mybb | * |
| mybb | mybb | 1.8.0 |
| mybb | mybb | 1.8.1 |
| mybb | mybb | 1.8.2 |
| mybb | mybb | 1.8.3 |
| mybb | mybb | 1.8.4 |
| mybb | mybb | 1.8.5 |
GitHub Security Advisory GHSA-9wjc-jp2f-45cq
SQL injection vulnerability in the Group Promotions module in the admin control panel in MyBB ...
References (8)
- http://www.openwall.com/lists/oss-security/2016/11/10/8 Third Party Advisory
- http://www.openwall.com/lists/oss-security/2016/11/18/1 Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/94397 Third Party Advisory, VDB Entry
- https://blog.mybb.com/2015/09/07/mybb-1-8-6-1-6-18-merge-system-1-8-6-release/ Release Notes, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2016/11/10/8 Third Party Advisory
- http://www.openwall.com/lists/oss-security/2016/11/18/1 Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/94397 Third Party Advisory, VDB Entry
- https://blog.mybb.com/2015/09/07/mybb-1-8-6-1-6-18-merge-system-1-8-6-release/ Release Notes, Vendor Advisory
Risk Scores
CVSS Score
10.0 / 10
EPSS Score
2.12%
Top 20% most likely to be exploited
Threat Score
40.6 / 100
Data Sources
NVD
EPSS
GitHub