CVE-2021-27949: XSS
Published Mar 15, 2021
·Updated
Cross-site Scripting vulnerability in MyBB before 1.8.26 via Custom moderator tools.
Affected Software
1 affected component
Mybb Mybb<1.8.26
Remediation
Event History
Mar 15, 2021
CVE Published
via MITRE·05:19 PM
Data Sourced
via MITRE·05:19 PM
Description
Frequently Asked Questions
1
What is CVE-2021-27949?
CVE-2021-27949 is a Cross-site Scripting vulnerability in MyBB before version 1.8.26 via Custom moderator tools.
2
How does the Cross-site Scripting vulnerability in MyBB before version 1.8.26 via Custom moderator tools work?
The Cross-site Scripting vulnerability in MyBB allows an attacker to inject malicious scripts into web pages viewed by other users, potentially leading to unauthorized access or manipulation of user data.
3
What software is affected by CVE-2021-27949?
The vulnerability affects MyBB versions before 1.8.26.
4
What is the severity of CVE-2021-27949?
The severity of CVE-2021-27949 is medium, with a CVSS score of 6.1.
5
How can I fix the Cross-site Scripting vulnerability in MyBB (CVE-2021-27949)?
To fix the vulnerability, it is recommended to update MyBB to version 1.8.26 or later, which includes a patch to mitigate the Cross-site Scripting vulnerability.