A Persistent XSS issue was discovered in the Visual Editor in MyBB before 1.8.19 via a Video MyCode.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://blog.mybb.com/2018/09/11/mybb-1-8-19-released-security-maintenance-release/ | release notes vendor advisory |
https://www.exploit-db.com/exploits/45449/ | exploit vdb entry third party advisory |