Cross-Site Scripting Vulnerability in MyBB Forum Software
CVE-2015-8976

6.1MEDIUM

Key Information:

Vendor

Mybb

Vendor
CVE Published:
31 January 2017

What is CVE-2015-8976?

A cross-site scripting vulnerability in MyBB, a popular forum software, allows remote attackers to inject arbitrary web scripts or HTML code. This vulnerability is particularly concerning in installations running outdated versions, including MyBB prior to 1.6.18 and 1.8.x before 1.8.6, as well as the MyBB Merge System before 1.8.6. Attackers can exploit this flaw through vectors involving outdated upgrade files, potentially compromising user security. It is essential for users and administrators to upgrade their installations to mitigate this risk.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.