CVE-2012-0829: Mibew Messenger

Medium severity, CVSS 6.0. EPSS: 0.9% chance of exploitation in the next 30 days.

Multiple cross-site request forgery (CSRF) vulnerabilities in Mibew Messenger 1.6.4 and earlier allow remote attackers to hijack the authentication of operators for requests that insert cross-site scripting (XSS) sequences via the (1) address or (2) threadid parameters to operator/ban.php; or (3) geolinkparams, (4) title, or (5) chattitle parameters to operator/settings.php.

Affected products

  • Mibew Mibew Messenger: up to and including 1.6.4; version 1.0.6 only; version 1.0.7 only; version 1.0.8 only; version 1.0.9 only; version 1.0.10 only; …

Published 2012-02-14. Last modified 2026-06-16.