Cross-Site Scripting Vulnerability in Active Threads Plugin for MyBB
CVE-2022-28354
6.1MEDIUM
What is CVE-2022-28354?
The Active Threads Plugin version 1.3.0 for MyBB contains a Cross-Site Scripting (XSS) vulnerability that can be exploited through the date parameter in the activethreads.php file. This flaw allows attackers to inject malicious scripts into web pages viewed by other users, potentially compromising the security of user accounts and sensitive information.