PT-2026-77179 · Mybb · Mybb
CVE-2026-45125
·
Published
2026-08-18
·
Updated
2026-08-18
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
MyBB versions prior to 1.8.40
Description
The Email User controller fails to properly sanitize sender names, leading to mail header injection. The endpoint 'member.php?action=do emailuser' accepts the
fromname parameter for guests or the stored username for authenticated users when the cansendemail group permission is active. If the mail handler is configured to the default PHP mail value, the sender name is inserted into Return-Path and Reply-To headers without sanitization, allowing the injection of arbitrary headers via CRLF (Carriage Return Line Feed) sequences. CRLF sequences are special characters used to signify the end of a line of text.Recommendations
Update to version 1.8.40.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mybb