Description
Cross-site scripting (XSS) vulnerability in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via vectors involving Mod control panel logs.
Remediation
References
Related Vulnerabilities
PleskWin Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2013-0132)
D3.js Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-16044)
Moodle Incorrect Authorization Vulnerability (CVE-2022-0984)
WordPress Plugin Tutor LMS-eLearning and online course solution Cross-Site Request Forgery (1.5.2)
osCommerce Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-27975)