The installer in MyBB before 1.8.13 has XSS.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://blog.mybb.com/2017/11/07/mybb-1-8-13-released-security-maintenance-release/ | release notes vendor advisory |
https://www.exploit-db.com/exploits/43137/ | exploit vdb entry third party advisory |