Description
MyBB 1.8.31 has a (issue 2 of 2) cross-site scripting (XSS) vulnerabilities in the post Attachments interface allow attackers to inject HTML by persuading the user to upload a file with specially crafted name
References
https://github.com/mybb/mybb/security/advisories/GHSA-p9m7-9qv4-x93w
PatchThird Party Advisory
Product
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
6.1 · Medium
CVSS V3.1
CVSS V3.0
CVSS V2.0
Information
Source identifier
Vulnerability status
Analyzed
Published
2022-11-22T00:15:12.007
2 years agoLast modified
2022-11-22T15:10:27.740
2 years ago