Description
Multiple cross-site scripting (XSS) vulnerabilities in MyBB (aka MyBulletinBoard) 1.4.14, and 1.6.x before 1.6.1, allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) editpost.php, (2) member.php, and (3) newreply.php.
Remediation
References
Related Vulnerabilities
WordPress Plugin Wordpress Picture/Portfolio/Media Gallery Server-Side Request Forgery (3.0.1)
OpenSSL Observable Differences in Behavior to Error Inputs Vulnerability (CVE-2019-1559)
Drupal Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-1591)
Python Improper Neutralization of CRLF Sequences ('CRLF Injection') Vulnerability (CVE-2019-9947)