vendor:
MyBB
by:
0xB9
8.8
CVSS
HIGH
Cross-Site Scripting, Cross-Site Request Forgery
79
CWE
Product Name: MyBB
Affected Version From: 1.1.2003
Affected Version To: 1.1.2003
Patch Exists: YES
Related CWE: CVE-2018-14575
CPE: a:mybb_group:mybb:1.1.3
Platforms Tested: Ubuntu 18.04
2018
MyBB Trash Bin Plugin 1.1.3 – Cross-Site Scripting / CSRF
Creates a trash bin in the ACP where you can recover permanent deleted threads and posts. The thread/post subjects allow XSS and deleted posts can be restored by CSRF.
Mitigation:
Update to version 1.1.4