Description
Cross-site scripting (XSS) vulnerability in the Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via vectors involving pruning logs.
Remediation
References
Related Vulnerabilities
WordPress Plugin Spreadsheet (wpSS) 'ss_id' Parameter SQL Injection (0.61)
Magento Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-8109)
PrestaShop CVE-2018-13784 Vulnerability (CVE-2018-13784)
WordPress Plugin WP Maps-Display Google Maps Perfectly with Ease Unspecified Vulnerability (3.1.6)
SugarCRM Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2019-17303)