8.8
CVSSv3

CVE-2018-14575

Published: 21/03/2019 Updated: 26/03/2019
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Trash Bin plugin 1.1.3 for MyBB has cross-site scripting (XSS) via a thread subject and a cross-site request forgery (CSRF) via a post subject.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mybb trash bin 1.1.3

Exploits

# Exploit Title: MyBB Trash Bin Plugin 113 - Cross-Site Scripting / CSRF # Date: 7/17/2018 # Author: 0xB9 # Twitter: @0xB9Sec # Contact: 0xB9[at]pmme # Software Link: communitymybbcom/modsphp?action=view&pid=957 # Version: 113 # Tested on: Ubuntu 1804 # CVE: CVE-2018-14575 1 Description: Creates a trash bin in the ACP where ...