CVE-2014-1840: XSS
Published Mar 3, 2014
·Updated
Cross-site scripting (XSS) vulnerability in Upload/search.php in MyBB 1.6.12 and earlier allows remote attackers to inject arbitrary web script or HTML via the keywords parameter in a dosearch action, which is not properly handled in a forced SQL error message.
Affected Software
13 affected components
Mybb Mybb<=1.6.12
Mybb Mybb=1.6.0
Mybb Mybb=1.6.1
Mybb Mybb=1.6.2
Mybb Mybb=1.6.3
Mybb Mybb=1.6.4
Mybb Mybb=1.6.5
Mybb Mybb=1.6.6
Mybb Mybb=1.6.7
Mybb Mybb=1.6.8
Mybb Mybb=1.6.9
Mybb Mybb=1.6.10
Mybb Mybb=1.6.11
Event History
Mar 3, 2014
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-1840?
CVE-2014-1840 has a medium severity rating due to the potential for remote script injection.
2
How do I fix CVE-2014-1840?
To fix CVE-2014-1840, upgrade to MyBB version 1.6.13 or later, which addresses this vulnerability.
3
What versions of MyBB are affected by CVE-2014-1840?
CVE-2014-1840 affects MyBB versions 1.6.12 and earlier.
4
What type of vulnerability is CVE-2014-1840?
CVE-2014-1840 is a cross-site scripting (XSS) vulnerability.
5
Can CVE-2014-1840 lead to data theft?
Yes, if exploited, CVE-2014-1840 can allow attackers to inject malicious scripts that may lead to data theft.