CVE-2015-8975: XSS
Published Jan 31, 2017
·Updated
Cross-site scripting (XSS) vulnerability in the error handler in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
8 affected components
MyBB Merge System=1.8.5
MyBB MyBB<=1.6.17
MyBB MyBB=1.8.0
MyBB MyBB=1.8.1
MyBB MyBB=1.8.2
MyBB MyBB=1.8.3
MyBB MyBB=1.8.4
MyBB MyBB=1.8.5
Event History
Jan 31, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Data Sourced
via NVD·10:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2015-8975?
CVE-2015-8975 is classified as a medium severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2015-8975?
To fix CVE-2015-8975, update MyBB to version 1.6.18 or 1.8.6 or later.
3
What versions of MyBB are affected by CVE-2015-8975?
CVE-2015-8975 affects MyBB versions prior to 1.6.18 and 1.8.x before 1.8.6.
4
Can CVE-2015-8975 lead to data theft?
Yes, CVE-2015-8975 could enable remote attackers to inject malicious scripts that may result in data theft.
5
Is the MyBB Merge System affected by CVE-2015-8975?
Yes, the MyBB Merge System is affected, specifically versions before 1.8.6.