cve/2018/CVE-2018-10580.md
2024-06-09 00:33:16 +00:00

935 B

CVE-2018-10580

Description

The "Latest Posts on Profile" plugin 1.1 for MyBB has XSS because there is an added section in a user profile that displays that user's most recent posts without sanitizing the tsubject (aka thread subject) field.

POC

Reference

Github

No PoCs found on GitHub currently.