vendor:
MyBB OUGC Awards Plugin
by:
0xB9
4.8
CVSS
MEDIUM
Cross-Site Scripting
79
CWE
Product Name: MyBB OUGC Awards Plugin
Affected Version From: 1.8.3
Affected Version To: 1.8.18
Patch Exists: YES
Related CWE: CVE-2019-3501
CPE: 2.3:a:mybb:mybb:1.8.3
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu 18.04
2018
MyBB OUGC Awards Plugin v1.8.3 – Cross-Site Scripting
OUGC Awards plugin for MyBB forum allows admins and moderators to grant awards to users which displays on profiles/posts. The reason input isn't sanitized on awards page and user profiles. Have a mod account level or higher, go to Manage Awards in ModCP, give an award to a user and input payload for reason <script>alert('XSS')</script> Payload executes when viewing award on awards.php and user profiles.
Mitigation:
Update to 1.8.19 or higher