Description
MyBB 1.8.31 has a (issue 2 of 2) cross-site scripting (XSS) vulnerabilities in the post Attachments interface allow attackers to inject HTML by persuading the user to upload a file with specially crafted name
References
https://github.com/mybb/mybb/security/advisories/GHSA-p9m7-9qv4-x93w
PatchThird Party Advisory
Product
https://github.com/mybb/mybb/security/advisories/GHSA-p9m7-9qv4-x93w
PatchThird Party Advisory
Product
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
6.1 · Medium
Information
Source identifier
Vulnerability status
Modified
Published
2022-11-21T23:15:12.007Z
3 years agoLast modified
2025-04-29T13:15:50.237Z
11 months ago