BIT-mybb-2020-19048

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/mybb/BIT-mybb-2020-19048.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-mybb-2020-19048
Aliases
  • CVE-2020-19048
Published
2024-03-06T11:00:24.160Z
Modified
2024-03-06T11:25:28.861Z
Summary
[none]
Details

Cross Site Scripting (XSS) in MyBB v1.8.20 allows remote attackers to inject arbitrary web script or HTML via the "Title" field found in the "Add New Forum" page by doing an authenticated POST HTTP request to '/Upload/admin/index.php?module=forum-management&action=add'.

Database specific
{
    "cpes": [
        "cpe:2.3:a:mybb:mybb:1.8.20:*:*:*:*:*:*:*"
    ],
    "severity": "Medium"
}
References

Affected packages

Bitnami / mybb

Package

Name
mybb
Purl
pkg:bitnami/mybb

Severity

  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
1.8.20
Last affected
1.8.20