AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2019-12831

HIGH · CVSS 7.2 EPSS 1.49%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-06-15 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2019-12831
Severity
HIGH
CVSS
7.2
EPSS
1.49%

Original NVD Description

In MyBB before 1.8.21, an attacker can abuse a default behavior of MySQL on many systems (that leads to truncation of strings that are too long for a database column) to create a PHP shell in the cache directory of a targeted forum via a crafted XML import, as demonstrated by truncation of aaaaaaaaaaaaaaaaaaaaaaaaaa.php.css to aaaaaaaaaaaaaaaaaaaaaaaaaa.php with a 30-character limit, aka theme import stylesheet name RCE.