Description
member.php in MyBB (aka MyBulletinBoard) before 1.4.12 makes a certain superfluous call to the SQL COUNT function, which allows remote attackers to cause a denial of service (resource consumption) by making requests to member.php that trigger scans of the entire users table.
Remediation
References
Related Vulnerabilities
MySQL CVE-2019-2695 Vulnerability (CVE-2019-2695)
Artifactory Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2021-23163)
WordPress Plugin Blog2Social:Social Media Auto Post & Scheduler Unspecified Vulnerability (5.1.2)
Plone CMS Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-5498)