cve/2018/CVE-2018-10580.md
2024-06-18 02:51:15 +02:00

783 B

CVE-2018-10580

Description

The "Latest Posts on Profile" plugin 1.1 for MyBB has XSS because there is an added section in a user profile that displays that user's most recent posts without sanitizing the tsubject (aka thread subject) field.

POC

Reference

Github

No PoCs found on GitHub currently.