Description
MyBB before 1.8.28 allows stored XSS because the displayed Template Name value in the Admin CP's theme management is not escaped properly.
Remediation
References
Related Vulnerabilities
e107 Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2018-17081)
Joomla Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2020-35611)
TYPO3 Session Fixation Vulnerability (CVE-2010-3671)
Apache HTTP Server CVE-2009-3720 Vulnerability (CVE-2009-3720)
Jenkins Improper Authentication Vulnerability (CVE-2014-2066)