CVE-2021-41866: XSS
Published Oct 26, 2021
·Updated
MyBB before 1.8.28 allows stored XSS because the displayed Template Name value in the Admin CP's theme management is not escaped properly.
Affected Software
1 affected component
Mybb Mybb<1.8.28
Remediation
Event History
Oct 26, 2021
CVE Published
via MITRE·09:25 PM
Data Sourced
via MITRE·09:25 PM
Description
Data Sourced
via NVD·10:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2021-41866.
2
What is the severity of CVE-2021-41866?
The severity of CVE-2021-41866 is medium (5.4).
3
What is the affected software of CVE-2021-41866?
The affected software is MyBB version up to exclusive 1.8.28.
4
What is the description of CVE-2021-41866?
CVE-2021-41866 is a stored XSS vulnerability in MyBB before 1.8.28, specifically in the displayed Template Name value in the Admin CP's theme management.
5
How can I fix CVE-2021-41866?
To fix CVE-2021-41866, upgrade MyBB to version 1.8.28 or later.