Description
A reflected XSS vulnerability in the ModCP Profile Editor in MyBB before 1.8.20 allows remote attackers to inject JavaScript via the 'username' parameter.
Remediation
References
Related Vulnerabilities
MediaWiki Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2021-36129)
Joomla! Core 3.x.x Security Bypass (3.8.13 - 3.9.6)
Apache Tomcat Improper Input Validation Vulnerability (CVE-2013-4322)
WordPress Plugin Email Log Cross-Site Scripting (2.2.2)
Grafana Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2022-23498)