MyBB Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2019-12830 - Vulnerability Database

MyBB Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2019-12830

High
Reference: CVE-2019-12830
Title: MyBB Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

In MyBB before 1.8.21 an attacker can exploit a parsing flaw in the Private Message / Post renderer that leads to video BBCode persistent XSS to take over any forum account aka a nested video MyCode issue.