CVE-2018-25248: MyBB Downloads Plugin 2.0.3 Persistent XSS via downloads.php
MyBB Downloads Plugin 2.0.3 contains a persistent cross-site scripting vulnerability that allows regular members to inject malicious scripts through the download title field. Attackers can submit a new download with HTML/JavaScript code in the title parameter, which executes when administrators validate the download in downloads.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-25248?
The severity of CVE-2018-25248 is classified as medium due to the potential for persistent cross-site scripting attacks.
How do I fix CVE-2018-25248?
To fix CVE-2018-25248, update the MyBB Downloads Plugin to a version that addresses this vulnerability.
Who is affected by CVE-2018-25248?
CVE-2018-25248 affects users of the MyBB Downloads Plugin version 2.0.3.
What type of vulnerability is CVE-2018-25248?
CVE-2018-25248 is a persistent cross-site scripting (XSS) vulnerability.
Can CVE-2018-25248 lead to data theft?
Yes, CVE-2018-25248 can allow attackers to inject scripts that may lead to data theft or session hijacking.