An CSRF issue was discovered in the JN-Jones MyBB-2FA plugin through 2014-11-05 for MyBB. An attacker can forge a request to an installed mybb2fa plugin to control its state via usercp.php?actionmybb2fa&dodeactivate (or usercp.php?actionmybb2fa&doactivate). A deactivate operation lowers the security of the targeted account by disabling two factor authentication.
Publication date: Thu, 11 Jul 2019 19:15:00 +0000