ZeroHour

CVE-2021-41866

CVSS 3.1
5.4 medium
EPSS
<1%p41
Published
()
Modified
Description

MyBB before 1.8.28 allows stored XSS because the displayed Template Name value in the Admin CP's theme management is not escaped properly.

Vendors
mybb
Products
mybb
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.