Description
Cross-site scripting (XSS) vulnerability in the Users module in the Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Remediation
References
Related Vulnerabilities
WordPress Plugin Viral Quiz Maker-OnionBuzz SQL Injection (1.2.1)
WordPress Plugin EventON Cross-Site Scripting (3.0.5)
WordPress Plugin FV Flowplayer Video Player Cross-Site Scripting (7.4.37.727)
WordPress Plugin WordPress Custom Global Variable Unspecified Vulnerability (3.0.0)
SugarCRM Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2019-17308)