CVE-2022-43708: XSS
Published Nov 21, 2022
·Updated
MyBB 1.8.31 has a (issue 2 of 2) cross-site scripting (XSS) vulnerabilities in the post Attachments interface allow attackers to inject HTML by persuading the user to upload a file with specially crafted name
Affected Software
1 affected component
Mybb Mybb<1.8.32
Remediation
Event History
Nov 21, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Nov 22, 2022
Data Sourced
via NVD·12:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this MyBB issue?
The vulnerability ID for this MyBB issue is CVE-2022-43708.
2
What is the severity of CVE-2022-43708?
The severity of CVE-2022-43708 is Medium.
3
What is the affected software version for CVE-2022-43708?
The affected software version for CVE-2022-43708 is MyBB 1.8.31 up to exclusive 1.8.32.
4
What is the CWE category for CVE-2022-43708?
The CWE category for CVE-2022-43708 is CWE-79.
5
How can attackers exploit CVE-2022-43708?
Attackers can exploit CVE-2022-43708 by persuading the user to upload a file with a specially crafted name, which allows them to inject HTML via cross-site scripting (XSS) vulnerabilities in the post Attachments interface.