CVE-2019-12830: XSS
Published Jun 15, 2019
·Updated
In MyBB before 1.8.21, an attacker can exploit a parsing flaw in the Private Message / Post renderer that leads to [video] BBCode persistent XSS to take over any forum account, aka a nested video MyCode issue.
Affected Software
1 affected component
Mybb Mybb<1.8.21
Event History
Jun 15, 2019
CVE Published
via MITRE·05:04 PM
Data Sourced
via MITRE·05:04 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-12830.
2
What is the severity of CVE-2019-12830?
The severity of CVE-2019-12830 is high with a severity value of 8.7.
3
How can an attacker exploit CVE-2019-12830?
An attacker can exploit CVE-2019-12830 by exploiting a parsing flaw in the MyBB Private Message / Post renderer and injecting malicious code through the [video] BBCode, leading to persistent XSS.
4
What is the affected software version for CVE-2019-12830?
The affected software version for CVE-2019-12830 is MyBB before 1.8.21.
5
How can the vulnerability in MyBB before 1.8.21 be fixed?
To fix the vulnerability in MyBB before 1.8.21, it is recommended to upgrade to version 1.8.21 or later.