Description
The my_rand function in functions.php in MyBB (aka MyBulletinBoard) before 1.4.12 does not properly use the PHP mt_rand function, which makes it easier for remote attackers to obtain access to an arbitrary account by requesting a reset of the account's password, and then conducting a brute-force attack.
Remediation
References
Related Vulnerabilities
Drupal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2009-4066)
WordPress Weak Password Recovery Mechanism for Forgotten Password Vulnerability (CVE-2014-6412)
WordPress Plugin File Manager Advanced Shortcode Arbitrary File Upload (2.5.3)
MongoDb Integer Underflow (Wrap or Wraparound) Vulnerability (CVE-2026-6914)