Cross-site Scripting (XSS) vulnerability in MyBB before 1.8.26 via Nested Auto URL when parsing messages.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/mybb/mybb/security/advisories/GHSA-xhj7-3349-mqcm | third party advisory patch |
http://packetstormsecurity.com/files/161908/MyBB-1.8.25-Remote-Command-Execution.html | exploit vdb entry third party advisory |
https://blog.sonarsource.com/mybb-remote-code-execution-chain | third party advisory exploit |