6.1
CVSSv3

CVE-2018-11532

Published: 29/05/2018 Updated: 29/06/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

An issue exists in the ChangUonDyU Advanced Statistics plugin 1.0.2 for MyBB. changstats.php has XSS, as demonstrated by a subject field.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

changuondyu advanced statistics project changuondyu advanced statistics 1.0.2

Exploits

# Exploit Title: MyBB ChangUonDyU Advanced Statistics Plugin v102 - Cross-Site Scripting # Date: 5/25/2018 # Author: 0xB9 # Twitter: @0xB9Sec # Contact: 0xB9[at]pmme # Software Link: communitymybbcom/modsphp?action=view&pid=1125 # Version: 102 # Tested on: Ubuntu 1804 # CVE: CVE-2018-11532 1 Description: This plugin displays ...
MyBB version 16x with ChangUonDyU Chatbox plugin version 360 suffers from a cross site scripting vulnerability ...
MyBB ChangUonDyU plugin version 102 suffers from a cross site scripting vulnerability ...