CVE-2023-53976: myBB Forums 1.8.26 Stored Cross-Site Scripting via Template Management
myBB Forums 1.8.26 contains a stored cross-site scripting vulnerability in the template management system that allows authenticated administrators to inject malicious scripts when creating new templates. Attackers can exploit this vulnerability by inserting script payloads in the template title field when adding new templates through the 'Templates and Style' > 'Templates' > 'Manage Templates' > 'Global Templates' interface, causing arbitrary JavaScript to execute when the template is viewed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-53976?
CVE-2023-53976 is classified as a medium severity vulnerability due to its potential for exploitation by authenticated users.
How do I fix CVE-2023-53976?
To fix CVE-2023-53976, update your myBB Forums to the latest version that addresses this vulnerability.
Who is affected by CVE-2023-53976?
Authenticated administrators using myBB Forums version 1.8.26 are affected by CVE-2023-53976.
What type of vulnerability is CVE-2023-53976?
CVE-2023-53976 is a stored cross-site scripting (XSS) vulnerability.
How can attackers exploit CVE-2023-53976?
Attackers can exploit CVE-2023-53976 by injecting malicious scripts into the template management system when creating new templates.