Description
MyBB 1.8.31 has a (issue 2 of 2) cross-site scripting (XSS) vulnerabilities in the post Attachments interface allow attackers to inject HTML by persuading the user to upload a file with specially crafted name
References
https://github.com/mybb/mybb/security/advisories/GHSA-p9m7-9qv4-x93w
PatchThird Party Advisory
Product
https://github.com/mybb/mybb/security/advisories/GHSA-p9m7-9qv4-x93w
PatchThird Party Advisory
Product
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
6.1 · Medium
Information
Source identifier
Vulnerability status
Modified
Published
2022-11-22T00:15:12.007Z
3 years agoLast modified
2026-06-17T05:07:11.307Z
3 months ago