CVE-2016-9404: XSS
Cross-site scripting (XSS) vulnerability in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via vectors related to login.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9404?
CVE-2016-9404 is classified as a medium severity vulnerability due to its potential for exploiting cross-site scripting.
How do I fix CVE-2016-9404?
The recommended fix for CVE-2016-9404 is to upgrade MyBB and MyBB Merge System to version 1.8.7 or later.
What types of attacks are possible with CVE-2016-9404?
CVE-2016-9404 allows remote attackers to perform cross-site scripting attacks, potentially injecting arbitrary web script or HTML.
Which versions of MyBB are affected by CVE-2016-9404?
CVE-2016-9404 affects MyBB versions prior to 1.8.7 and MyBB Merge System versions prior to 1.8.7.
Can CVE-2016-9404 be exploited without user interaction?
Yes, CVE-2016-9404 can be exploited by attackers without user interactions if users visit a specially crafted login page.