CVE-2012-1602: Nextbbs

High severity, CVSS 7.5. EPSS: 2.1% chance of exploitation in the next 30 days.

user.php in NextBBS 0.6 allows remote attackers to bypass authentication and gain administrator access by setting the userkey cookie to 1.

Affected products

Published 2012-10-01. Last modified 2026-06-16.