Description
A reflected XSS vulnerability in index.php in MyBB 1.8.x through 1.8.19 allows remote attackers to inject JavaScript via the 'upsetting[bburl]' parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin WordPress.com Custom CSS Cross-Site Scripting (1.5)
WordPress Plugin RSVPmaker Excel Cross-Site Scripting (1.1)
Magento Insufficient Session Expiration Vulnerability (CVE-2019-8149)
Jboss EAP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2013-4112)
WordPress Plugin Debug Log Manager Information Disclosure (2.2.2)