Description
In MyBB before 1.8.21, an attacker can exploit a parsing flaw in the Private Message / Post renderer that leads to [video] BBCode persistent XSS to take over any forum account, aka a nested video MyCode issue.
Remediation
References
Related Vulnerabilities
WordPress Plugin Custom Sidebars-Dynamic Widget Area Manager Multiple Vulnerabilities (3.0.8)
WordPress Plugin Simple SEO Cross-Site Scripting (1.7.91)
Ruby Improper Authentication Vulnerability (CVE-2008-3905)
WordPress Plugin Disable Image Right Click Cross-Site Scripting (1.0)
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-2165)