MyBB 1.8.31 has a (issue 2 of 2) cross-site scripting (XSS) vulnerabilities in the post Attachments interface allow attackers to inject HTML by persuading the user to upload a file with specially crafted name
References
Link | Resource |
---|---|
https://github.com/mybb/mybb/security/advisories/GHSA-p9m7-9qv4-x93w | Patch Third Party Advisory |
https://mybb.com | Product |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2022-11-21T00:00:00
Updated: 2022-11-21T00:00:00
Reserved: 2022-10-24T00:00:00
Link: CVE-2022-43708
JSON object: View
NVD Information
Status : Analyzed
Published: 2022-11-22T00:15:12.007
Modified: 2022-11-22T15:10:27.740
Link: CVE-2022-43708
JSON object: View
Redhat Information
No data.
CWE