6.1
CVSSv3

CVE-2018-14888

Published: 14/08/2018 Updated: 12/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

inc/plugins/thankyoulike.php in the Eldenroot Thank You/Like plugin prior to 3.1.0 for MyBB allows XSS via a post or thread subject.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

thank you\\/like project thank you\\/like

Exploits

# Exploit Title: MyBB Thank You/Like Plugin 300 - Cross-Site Scripting # Date: 8/1/2018 # Author: 0xB9 # Twitter: @0xB9Sec # Contact: 0xB9[at]pmme # Software Link: communitymybbcom/modsphp?action=view&pid=360 # Version: 300 # Tested on: Ubuntu 1804 # CVE: CVE-2018-14888 1 Description: This plugin allows users to thank/like o ...
MyBB Thank You and Like plugins version 300 suffer from a cross site scripting vulnerability ...