vendor:
MyBB
by:
Avinash Kumar Thapa
7,5
CVSS
HIGH
Stored Cross-Site Scripting (XSS)
79
CWE
Product Name: MyBB
Affected Version From: MyBB 1.8.2
Affected Version To: MyBB 1.8.2
Patch Exists: Yes
Related CWE: N/A
CPE: a:mybb:mybb:1.8.2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 8.1, Mozilla Firefox 33.1
2014
Stored XSS vulnerability in MyBB 1.8.2
The latest version of MyBB forums (1.8.2) is vulnerable to Stored Cross-Site Scripting (XSS) vulnerability. An attacker can exploit this vulnerability by creating a user account and going to User CP > Edit Profile > Custom User Title and entering a malicious vector such as <img src=x onerror=alert('XSS');>. When a user visits the calendar page, the XSS alert box will be triggered.
Mitigation:
MyBB has released a patch to address this vulnerability. Users should upgrade to the latest version of MyBB.