Description
MyBB (aka MyBulletinBoard) before 1.4.12 allows remote authenticated users to bypass intended restrictions on the number of [img] MyCodes by editing a post after it has been created.
Remediation
References
Related Vulnerabilities
WordPress Plugin Comment Attachment Cross-Site Scripting (1.5.5)
SharePoint Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-1024)
WordPress Plugin Mailing List 'dl.php' Arbitrary File Download (1.4.1)
Drupal Core 8.9.x Multiple Security Bypass Vulnerabilities (8.9.0 - 8.9.18)