Description
An issue was discovered in inc/class_feedgeneration.php in MyBB 1.8.17. On the forum RSS Syndication page, one can generate a URL such as http://localhost/syndication.php?fid=&type=atom1.0&limit=15. The thread titles (within title elements of the generated XML documents) aren't sanitized, leading to XSS.
Remediation
References
Related Vulnerabilities
WordPress Plugin Gallery by BestWebSoft Cross-Site Scripting (4.4.9)
WordPress Plugin xili-tidy-tags Cross-Site Request Forgery (1.12.03)
PHP Improper Input Validation Vulnerability (CVE-2020-7071)
WordPress Plugin CM Download Manager Multiple Vulnerabilities (2.0.6)
Drupal Improper Input Validation Vulnerability (CVE-2013-6389)