CVE-2023-53977: myBB Forums 1.8.26 Stored Cross-Site Scripting via Forum Management
myBB Forums 1.8.26 contains a stored cross-site scripting vulnerability in the forum management system that allows authenticated administrators to inject malicious scripts when creating new forums. Attackers can exploit this vulnerability by inserting script payloads in the forum title field when adding new forums through the 'Forums and Posts' > 'Forum Management' interface, causing arbitrary JavaScript to execute when the forum listing is viewed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-53977?
CVE-2023-53977 is rated as a high severity stored cross-site scripting vulnerability.
How can I fix CVE-2023-53977?
To fix CVE-2023-53977, upgrade your myBB Forums software to version 1.8.27 or later.
Who is affected by CVE-2023-53977?
Authenticated administrators using myBB Forums version 1.8.26 are affected by CVE-2023-53977.
What kind of vulnerability is CVE-2023-53977?
CVE-2023-53977 is a stored cross-site scripting (XSS) vulnerability.
What impact does CVE-2023-53977 have?
Exploitation of CVE-2023-53977 can allow an attacker to inject and execute malicious scripts in the context of the forum management system.