3.5
CVSSv2

CVE-2017-16781

Published: 10/11/2017 Updated: 27/11/2017
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 355
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

The installer in MyBB prior to 1.8.13 has XSS.

Vulnerable Product Search on Vulmon Subscribe to Product

mybb mybb

Exploits

# Exploit Title: XSS in MyBB up to 1813 via installer # Date: Found on 05-29-2017 # Exploit Author: Pablo Sacristan # Vendor Homepage: mybbcom/ # Version: Version > 1813 (Fixed in 1813) # CVE : CVE-2017-16781 No HTML escaping when returning an $error in /install/indexphp can lead to an XSS which can be used to take over an attac ...