CVE-2016-9409: XSS
Cross-site scripting (XSS) vulnerability in the Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via vectors involving pruning logs.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9409?
CVE-2016-9409 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2016-9409?
To fix CVE-2016-9409, upgrade MyBB to version 1.8.7 or later, which includes a patch for this vulnerability.
Who is affected by CVE-2016-9409?
CVE-2016-9409 affects users of MyBB versions prior to 1.8.7 and the MyBB Merge System before version 1.8.7.
What type of vulnerability is CVE-2016-9409?
CVE-2016-9409 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary web scripts or HTML.
What can attackers do with CVE-2016-9409?
Attackers exploiting CVE-2016-9409 could potentially execute malicious scripts in the context of a victim's session.