CVE-2026-45118

Summary

MyBB is free and open source forum software. Prior to 1.8.40, the Contact module does not validate a redirect URL or protocol correctly, resulting in an open redirect and reflected JavaScript code injection. contact.php accepts the redirect target from the from HTTP parameter in $mybb->input['from'] or the Referer HTTP header in $_SERVER['HTTP_REFERER'] and passes it to redirect() without sufficient verification. A javascript: URI becomes the target of the Click here if you don't want to wait any longer link because $force_redirect is true, allowing script execution when a victim selects the link. This issue is fixed in version 1.8.40.

Affected Software

VendorProductVersion RangeStatus
mybbmybb< 1.8.40affected

Weaknesses

  • CWE-83: CWE-83: Improper Neutralization of Script in Attributes in a Web Page

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References