CVE-2023-45556: XSS
Cross Site Scripting vulnerability in Mybb Mybb Forums v.1.8.33 allows a local attacker to execute arbitrary code via the theme Name parameter in the theme management component.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-45556?
CVE-2023-45556 is a Cross Site Scripting vulnerability in Mybb Mybb Forums v.1.8.33 that allows a local attacker to execute arbitrary code via the theme Name parameter in the theme management component.
How severe is CVE-2023-45556?
CVE-2023-45556 has a severity level of medium with a CVSS score of 5.4.
How does CVE-2023-45556 impact Mybb Mybb Forums?
CVE-2023-45556 allows a local attacker to execute arbitrary code in Mybb Mybb Forums v.1.8.33 through the theme Name parameter in the theme management component.
What are the affected software versions of CVE-2023-45556?
CVE-2023-45556 affects Mybb Mybb Forums versions 1.8.33 up to but excluding 1.8.37.
Is there a fix for CVE-2023-45556?
Yes, the Mybb Mybb Forums developers have released a fix for CVE-2023-45556. It is recommended to update to version 1.8.37 or above to mitigate the vulnerability.