Description
MyBB (aka MyBulletinBoard) 1.4.2 does not properly handle an uploaded file with a nonstandard file type that contains HTML sequences, which allows remote attackers to cause that file to be processed as HTML by Internet Explorer's content inspection, aka "Incomplete protection against MIME-sniffing." NOTE: this could be leveraged for XSS and other attacks.
Remediation
References
Related Vulnerabilities
TYPO3 Generation of Error Message Containing Sensitive Information Vulnerability (CVE-2025-59016)
WordPress Plugin Spryng Payments for WooCommerce Cross-Site Scripting (1.6.7)
WordPress Plugin Flight Search Widget and Blocks Cross-Site Scripting (1.1.0)
WordPress Plugin Drag and Drop Multiple File Upload-Contact Form 7 Arbitrary File Upload (1.3.3.2)