4.3
CVSSv2

CVE-2021-27889

Published: 15/03/2021 Updated: 21/09/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site Scripting (XSS) vulnerability in MyBB prior to 1.8.26 via Nested Auto URL when parsing messages.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mybb mybb

Exploits

MyBB version 1825 chain remote command execution exploit that leverages cross site scripting and SQL injection vulnerabilities ...
MyBB version 1825 suffers from a remote SQL injection vulnerability ...

Github Repositories

Mybb associate CVE-2021-27890 & CVE-2021-27889 to RCE poc

Mybb-XSS_SQL_RCE-POC Mybb associate CVE-2021-27890 & CVE-2021-27889 to RCE poc Before Use: There are two files here: 1js and attack_listenpy You should modify these two file: 1js: modify the mybb forum url and attack url: var bashurl = '19216892164/mybb/mybb-mybb_1825' #mybb forum url var attack_url = '19216892165:8080/attack_succ