CVE-2022-43707: XSS
MyBB 1.8.31 has a Cross-site scripting (XSS) vulnerability in the visual MyCode editor (SCEditor) allows remote attackers to inject HTML via user input or stored data
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this MyBB vulnerability?
The vulnerability ID for this MyBB vulnerability is CVE-2022-43707.
What is the affected software for this vulnerability?
The affected software for this vulnerability is MyBB version up to and excluding 1.8.32.
What is the severity of the CVE-2022-43707 vulnerability?
The severity of the CVE-2022-43707 vulnerability is medium, with a CVSS score of 6.1.
How does this vulnerability occur?
This vulnerability occurs due to a Cross-site scripting (XSS) vulnerability in the visual MyCode editor (SCEditor), which allows remote attackers to inject HTML via user input or stored data.
How can I fix the CVE-2022-43707 vulnerability?
To fix the CVE-2022-43707 vulnerability, upgrade MyBB to version 1.8.32 or higher, which addresses the Cross-site scripting (XSS) vulnerability in the visual MyCode editor (SCEditor).