An issue was discovered in inc/class_feedgeneration.php in MyBB 1.8.17. On the forum RSS Syndication page, one can generate a URL such as http://localhost/syndication.php?fid=&type=atom1.0&limit=15. The thread titles (within title elements of the generated XML documents) aren't sanitized, leading to XSS.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2018-08-28T19:00:00

Updated: 2018-09-14T09:57:02

Reserved: 2018-08-20T00:00:00


Link: CVE-2018-15596

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-08-28T19:29:16.553

Modified: 2018-11-08T13:19:40.707


Link: CVE-2018-15596

JSON object: View

cve-icon Redhat Information

No data.

CWE