Description
Cross-site request forgery (CSRF) vulnerability in global.php in MyBB before 1.6.5 allows remote attackers to hijack the authentication of a user for requests that change the user's language via the language parameter.
Remediation
References
Related Vulnerabilities
Grafana URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2022-29170)
Oracle HTTP Server Integer Overflow or Wraparound Vulnerability (CVE-2022-22721)
WordPress CVE-2020-28039 Vulnerability (CVE-2020-28039)
Liferay Portal Origin Validation Error Vulnerability (CVE-2022-25146)
WordPress Plugin wpForo Forum Multiple Vulnerabilities (2.1.7)