vendor:
Profile Skype ID MyBB Plugin
by:
limb0
7,5
CVSS
HIGH
Stored XSS
79
CWE
Product Name: Profile Skype ID MyBB Plugin
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: Yes
Related CWE: N/A
CPE: mybb:user_profile_skype_id
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2012
Profile Skype ID MyBB Plugin Stored XSS
The Profile Skype ID MyBB Plugin is vulnerable to stored XSS. An attacker can inject malicious JavaScript code into the Skype ID field of a user profile. When a user visits the profile, the malicious code will be executed in the user's browser.
Mitigation:
The vendor has released an update to address this vulnerability. Users should update to the latest version of the Profile Skype ID MyBB Plugin.