CVE-2018-19202: XSS
Published Apr 11, 2019
·Updated
A reflected XSS vulnerability in index.php in MyBB 1.8.x through 1.8.19 allows remote attackers to inject JavaScript via the 'upsetting[bburl]' parameter.
Affected Software
1 affected component
Mybb Mybb>=1.8.0<1.8.20
Event History
Apr 11, 2019
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2018-19202.
2
What is the title of the vulnerability?
The title of the vulnerability is 'A reflected XSS vulnerability in index.php in MyBB 1.8.x through 1.8.19 allows remote attackers to inject JavaScript via the 'upsetting[bburl]' parameter.'
3
What is the affected software?
The affected software is MyBB version 1.8.x through 1.8.19.
4
How severe is the vulnerability?
The severity of the vulnerability is medium, with a CVSS score of 6.1.
5
How can I fix the vulnerability?
To fix the vulnerability, update MyBB to version 1.8.20 or later.