CVE-2016-9421: XSS
Cross-site scripting (XSS) vulnerability in the Users module in the Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9421?
CVE-2016-9421 is classified as a high severity vulnerability due to its potential exploitation for cross-site scripting attacks.
How do I fix CVE-2016-9421?
To fix CVE-2016-9421, upgrade to MyBB version 1.8.8 or later or the corresponding updated version of MyBB Merge System.
What type of attack does CVE-2016-9421 allow?
CVE-2016-9421 allows remote attackers to perform cross-site scripting (XSS) attacks by injecting arbitrary web scripts or HTML.
Which versions of MyBB are affected by CVE-2016-9421?
CVE-2016-9421 affects MyBB versions before 1.8.8 and MyBB Merge System versions before 1.8.8.
What components are vulnerable in CVE-2016-9421?
CVE-2016-9421 is specifically a vulnerability in the Users module of the Admin control panel within MyBB.