CVE-2023-28467: XSS
Published May 22, 2023
·Updated
In MyBB before 1.8.34, there is XSS in the User CP module via the user email field.
Affected Software
1 affected component
Mybb Mybb<1.8.34
Remediation
Event History
May 22, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this MyBB vulnerability?
The vulnerability ID for this MyBB vulnerability is CVE-2023-28467.
2
What is the severity of CVE-2023-28467?
The severity of CVE-2023-28467 is medium.
3
What is the affected software for CVE-2023-28467?
The affected software for CVE-2023-28467 is MyBB version up to and excluding 1.8.34.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-28467?
The Common Weakness Enumeration (CWE) ID for CVE-2023-28467 is CWE-79.
5
How do I fix CVE-2023-28467?
To fix CVE-2023-28467, you should update MyBB to version 1.8.34 or newer.