Executive brief
The Timeline plugin for MyBB forum software, which replaces standard user profiles with a timeline view, contains security flaws that allow for unauthorized script execution and profile modification. Attackers can inject malicious code into forum posts or user profiles that runs when other users view them, potentially leading to account compromise or site defacement. Additionally, a flaw in how the plugin handles requests allows attackers to force users into changing their profile cover images without their consent.
Technical details
The MyBB Timeline Plugin 1.0 fails to properly sanitize user-supplied input in several fields, leading to persistent Cross-Site Scripting (XSS). Specifically, malicious scripts can be injected via thread titles, post content, and user profile fields such as 'Location' and 'Bio'; these scripts execute in the context of any user viewing the affected profile or thread. Additionally, the 'timeline.php' profile action lacks proper request validation, making it susceptible to Cross-Site Request Forgery (CSRF). This allows an attacker to craft a malicious form that, when submitted by an authenticated victim, changes the victim's profile cover picture. These vulnerabilities were publicly disclosed with proof-of-concept exploits in early 2021.
Affected products
- MyBB Timeline Plugin 1.0
Timeline
- 2021-01-21: disclosed: Initial discovery and report by researcher 0xB9
- 2021-01-25: other: Exploit published on Exploit-DB
- 2026-05-16: advisory: CVE record published and NVD dataset updated