Description
Cross-site scripting (XSS) vulnerability in the User control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Remediation
References
Related Vulnerabilities
Serendipity Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2016-10752)
WordPress Plugin Spam protection, AntiSpam, FireWall by CleanTalk Cross-Site Scripting (5.21)
Drupal Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-2687)
concrete5 Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-5107)
WordPress 3.1.3 Multiple SQL Injection Vulnerabilities (3.1 - 3.1.3)