Description
Cross-site scripting (XSS) vulnerability in the User control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Remediation
References
Related Vulnerabilities
WordPress Plugin Word Balloon Cross-Site Scripting (4.19.2)
WordPress Plugin Admin Menu Tree Page View Multiple Vulnerabilities (2.6.9)
PHP Other Vulnerability (CVE-2015-8866)
WordPress 3.7.x Multiple Vulnerabilities (3.7 - 3.7.16)
WordPress Plugin Lightbox Multiple Unspecified Vulnerabilities (2.0.7)