Description
Cross-site scripting (XSS) vulnerability in MyBB before 1.6.13 allows remote authenticated users to inject arbitrary web script or HTML via the name parameter in the edit action of the config-profile_fields module.
Remediation
References
Related Vulnerabilities
PHP Other Vulnerability (CVE-2015-7803)
Joomla! Core Directory Traversal (2.5.0 - 3.9.22)
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-11145)
WordPress Plugin FreshMail For WordPress Multiple SQL Injection Vulnerabilities (1.5.8)
Drupal Improper Access Control Vulnerability (CVE-2016-3165)