MyBB before 1.8.28 allows stored XSS because the displayed Template Name value in the Admin CP's theme management is not escaped properly.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/mybb/mybb/security/advisories/ | third party advisory |
https://github.com/mybb/mybb/security/advisories/GHSA-gxhv-r3m5-6qv7 | third party advisory patch |