Important security announcement regarding MyBB merge system versions 1.6.1 and earlier.

If you’ve used the MyBB Merge System v1.6.1 or earlier please download the file attached here, upload it to your forum root, and run it by going to http://yourdomain.com/yourforumpath/icr.php for security purposes.

The reason for this is a potential security breach related to the “old db” password being stored in the datacache in plaintext form. Thanks goes to euantor & Malcolm for reporting this.

5 thoughts on “Important security announcement regarding MyBB merge system versions 1.6.1 and earlier.

  1. Dylan, it wasn’t euantor who found it, it was me. But I do not want credit, I just wanted to let you know that it had been reported a while ago :P

  2. I didn’t thank him for finding it, but for reporting :P
    But thank you too ;)

    I had honestly forgotten all about that thread, so I’m glad you mentioned it. This is why I put things on the bug tracker as soon as I read a post now.

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Connecting to %s