SQL Injection Vulnerability in MyBB and MyBB Merge System
CVE-2016-9416
9.8CRITICAL
What is CVE-2016-9416?
An SQL injection vulnerability exists in the users data handler of MyBB and the MyBB Merge System, allowing remote attackers to execute arbitrary SQL commands. This flaw emerges due to improper input validation, potentially leading to unauthorized database access or data manipulation. Users are urged to upgrade to MyBB version 1.8.8 or later to mitigate this security risk.