CVE-2019-3579

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
06/06/2019
Last modified:
30/06/2025

Description

MyBB 1.8.19 allows remote attackers to obtain sensitive information because it discloses the username upon receiving a password-reset request that lacks the code parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mybb:mybb:1.8.19:*:*:*:*:*:*:*