vendor:
MyBB Thread Redirect Plugin
by:
0xB9
7.5
CVSS
HIGH
Cross-Site Scripting
79
CWE
Product Name: MyBB Thread Redirect Plugin
Affected Version From: 0.2.1
Affected Version To: 0.2.1
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10
2018
MyBB Thread Redirect Plugin 0.2.1 – Cross-Site Scripting
This plugin allows threads to redirect to a URL with optional custom text. The custom text input is vulnerable to Cross-Site Scripting. Anyone who views the thread will execute payload.
Mitigation:
Upgrade to version 0.2.2 or later.