CVE-2024-52702: XSS
A stored cross-site scripting (XSS) vulnerability in the component install\index.php of MyBB v1.8.38 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Website Name parameter. NOTE: this is disputed by the Supplier because Website Name can only be set by an administrator, who may use JavaScript if they wish.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52702?
CVE-2024-52702 is classified as a high-severity stored cross-site scripting vulnerability.
How do I fix CVE-2024-52702?
To fix CVE-2024-52702, update MyBB to version 1.8.39 or later, which addresses the vulnerability.
What are the consequences of exploiting CVE-2024-52702?
Exploiting CVE-2024-52702 can allow attackers to execute arbitrary web scripts or HTML, potentially compromising user data and site integrity.
Which component is affected by CVE-2024-52702?
CVE-2024-52702 affects the install/index.php component of MyBB version 1.8.38.
Who is affected by CVE-2024-52702?
Anyone using MyBB version 1.8.38 without applying the latest patches may be affected by CVE-2024-52702.