Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 18 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mybb
Mybb mybb |
|
| Vendors & Products |
Mybb
Mybb mybb |
Tue, 18 Aug 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MyBB is free and open source forum software. Prior to 1.8.40, the Email User controller does not sanitize sender names correctly, resulting in mail header injection. member.php?action=do_emailuser accepts the fromname HTTP parameter for guests or the stored username for authenticated users when the cansendemail group permission is enabled. When mail_handler is set to the default PHP mail value, the sender name is used without sanitization in Return-Path and Reply-To headers, allowing arbitrary headers to be injected with CRLF sequences. This issue is fixed in version 1.8.40. | |
| Title | MyBB: Email User CRLF injection | |
| Weaknesses | CWE-93 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-18T17:46:25.763Z
Reserved: 2026-05-08T20:08:17.208Z
Link: CVE-2026-45125
No data.
Status : Received
Published: 2026-08-18T16:17:07.667
Modified: 2026-08-18T18:17:36.450
Link: CVE-2026-45125
No data.
OpenCVE Enrichment
Updated: 2026-08-18T18:15:04Z
-
CWE-93
Improper Neutralization of CRLF Sequences ('CRLF Injection')