CVE-2013-7275: XSS
Cross-site scripting (XSS) vulnerability in misc.php in MyBB (aka MyBulletinBoard) before 1.6.12 allows remote attackers to inject arbitrary web script or HTML via the editor parameter in a smilie list popup.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-7275?
CVE-2013-7275 is classified as a high severity vulnerability due to its potential to allow attackers to execute arbitrary scripts.
How do I fix CVE-2013-7275?
To fix CVE-2013-7275, upgrade to MyBB version 1.6.12 or later where the vulnerability has been patched.
What types of attacks can CVE-2013-7275 facilitate?
CVE-2013-7275 can facilitate cross-site scripting (XSS) attacks, which allow attackers to inject and execute malicious scripts in a user's browser.
Which versions of MyBB are affected by CVE-2013-7275?
CVE-2013-7275 affects MyBB versions prior to 1.6.12, including multiple earlier versions.
Is there a workaround for CVE-2013-7275 if I can’t update MyBB?
If an immediate update isn't possible for CVE-2013-7275, restrict access to input fields in the frontend to minimize exposure to the vulnerability.