MyBB Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2018-19201 - Vulnerability Database
MyBB Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2018-19201
Medium
Reference:
CVE-2018-19201
Title:
MyBB Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:
A reflected XSS vulnerability in the ModCP Profile Editor in MyBB before 1.8.20 allows remote attackers to inject JavaScript via the 39username39 parameter.