In MyBB before 1.8.34, there is XSS in the User CP module via the user email field.
References
Link Resource
https://github.com/mybb/mybb/security/advisories/GHSA-3q8x-9fh2-v646 Patch Release Notes Third Party Advisory
https://mybb.com Product
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2023-05-22T00:00:00

Updated: 2023-05-22T00:00:00

Reserved: 2023-03-15T00:00:00


Link: CVE-2023-28467

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-05-22T19:15:10.017

Modified: 2023-05-27T01:49:32.293


Link: CVE-2023-28467

JSON object: View

cve-icon Redhat Information

No data.

CWE