CVE-2022-28354: XSS
Published Apr 24, 2023
·Updated
In the Active Threads Plugin 1.3.0 for MyBB, the activethreads.php date parameter is vulnerable to XSS when setting a time period.
Affected Software
1 affected component
MyBB Active Threads=1.3.0
Event History
Apr 24, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this MyBB Active Threads Plugin vulnerability?
The vulnerability ID for this MyBB Active Threads Plugin vulnerability is CVE-2022-28354.
2
What is the title of this vulnerability?
The title of this vulnerability is 'In the Active Threads Plugin 1.3.0 for MyBB the activethreads.php date parameter is vulnerable to XSS'.
3
What is the affected software for this vulnerability?
The affected software for this vulnerability is MyBB Active Threads Plugin version 1.3.0.
4
What is the severity of CVE-2022-28354?
The severity of CVE-2022-28354 is medium with a severity value of 6.1.
5
How can I fix the MyBB Active Threads Plugin vulnerability?
To fix the MyBB Active Threads Plugin vulnerability, update to a version that is not affected by the vulnerability.