Description
Cross-site request forgery (CSRF) vulnerability in global.php in MyBB before 1.6.5 allows remote attackers to hijack the authentication of a user for requests that change the user's language via the language parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin YITH Pre-Order for WooCommerce Security Bypass (1.1.9)
Oracle Database Server CVE-2023-21949 Vulnerability (CVE-2023-21949)
WebLogic CVE-2022-21257 Vulnerability (CVE-2022-21257)
Oracle Database Server Other Vulnerability (CVE-2007-0276)
Apache Tomcat Improper Encoding or Escaping of Output Vulnerability (CVE-2022-45143)