CVE-2018-19201: XSS
Published Mar 29, 2019
·Updated
A reflected XSS vulnerability in the ModCP Profile Editor in MyBB before 1.8.20 allows remote attackers to inject JavaScript via the 'username' parameter.
Affected Software
1 affected component
Mybb Mybb<1.8.20
Event History
Mar 29, 2019
CVE Published
via MITRE·06:58 PM
Data Sourced
via MITRE·06:58 PM
Description
Frequently Asked Questions
1
What is CVE-2018-19201?
CVE-2018-19201 is a reflected XSS vulnerability in the ModCP Profile Editor in MyBB before version 1.8.20.
2
How does CVE-2018-19201 affect MyBB?
CVE-2018-19201 allows remote attackers to inject JavaScript via the 'username' parameter in the ModCP Profile Editor in MyBB before version 1.8.20.
3
What is the severity of CVE-2018-19201?
CVE-2018-19201 has a severity rating of medium with a CVSS score of 6.1.
4
How can I fix CVE-2018-19201?
To fix CVE-2018-19201, upgrade MyBB to version 1.8.20 or newer.
5
Where can I find more information about CVE-2018-19201?
You can find more information about CVE-2018-19201 in the MyBB blog and GitHub security advisories.