CVE-2018-25250: MyBB Last User's Threads in Profile Plugin 1.2 Persistent XSS
MyBB Last User's Threads in Profile Plugin 1.2 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts by crafting thread subjects with script tags. Attackers can create threads with script payloads in the subject field that execute when users visit the attacker's profile page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-25250?
The severity of CVE-2018-25250 is considered to be high due to its persistent cross-site scripting nature.
How do I fix CVE-2018-25250?
To fix CVE-2018-25250, update the MyBB Last User's Threads in Profile Plugin to version 1.3 or later.
What type of vulnerability is CVE-2018-25250?
CVE-2018-25250 is classified as a persistent cross-site scripting (XSS) vulnerability.
Can CVE-2018-25250 be exploited remotely?
Yes, CVE-2018-25250 can be exploited remotely by an attacker injecting malicious scripts through thread subjects.
Who is affected by CVE-2018-25250?
CVE-2018-25250 affects users of MyBB Last User's Threads in Profile Plugin version 1.2.