4.3
CVSSv2

CVE-2018-15596

Published: 28/08/2018 Updated: 08/11/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

An issue exists in inc/class_feedgeneration.php in MyBB 1.8.17. On the forum RSS Syndication page, one can generate a URL such as localhost/syndication.php?fid=&type=atom1.0&limit=15. The thread titles (within title elements of the generated XML documents) aren't sanitized, leading to XSS.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mybb mybb 1.8.17

Exploits

# Exploit Title: MyBB 1817 - Cross-Site Scripting # Date: 2018-08-11 # Author: 0xB9 # Twitter: @0xB9Sec # Contact: 0xB9[at]pmme # Software Link: mybbcom/download/ # Version: 1817 # Tested on: Ubuntu 1804 # CVE: CVE-2018-15596 # 1 Description: # On the forum RSS Syndication page you can generate a URL for example # localh ...
MyBB version 1817 suffers from a cross site scripting vulnerability ...