From d0348403d45cffc7478c7c90299401b0ead03a01 Mon Sep 17 00:00:00 2001 From: CVE Team Date: Mon, 10 Aug 2020 22:01:38 +0000 Subject: [PATCH] "-Synchronized-Data." --- 2020/15xxx/CVE-2020-15139.json | 2 +- 2020/15xxx/CVE-2020-15701.json | 7 ++++++- 2020/15xxx/CVE-2020-15702.json | 7 ++++++- 3 files changed, 13 insertions(+), 3 deletions(-) diff --git a/2020/15xxx/CVE-2020-15139.json b/2020/15xxx/CVE-2020-15139.json index 94b54706ccf..0efffca498e 100644 --- a/2020/15xxx/CVE-2020-15139.json +++ b/2020/15xxx/CVE-2020-15139.json @@ -35,7 +35,7 @@ "description_data": [ { "lang": "eng", - "value": "In MyBB before version 1.8.24, the custom MyCode (BBCode) for the visual editor doesn't escape input properly when rendering HTML, resulting in a DOM-based XSS vulnerability.\n\nThe weakness can be exploited by pointing a victim to a page where the visual editor is active (e.g. as a post or Private Message) and operates on a maliciously crafted MyCode message. This may occur on pages where message content is pre-filled using a GET/POST parameter, or on reply pages where a previously saved malicious message is quoted.\n\nAfter upgrading MyBB to 1.8.24, make sure to update the version attribute in the `codebuttons` template for non-default themes to serve the latest version of the patched `jscripts/bbcodes_sceditor.js` file." + "value": "In MyBB before version 1.8.24, the custom MyCode (BBCode) for the visual editor doesn't escape input properly when rendering HTML, resulting in a DOM-based XSS vulnerability. The weakness can be exploited by pointing a victim to a page where the visual editor is active (e.g. as a post or Private Message) and operates on a maliciously crafted MyCode message. This may occur on pages where message content is pre-filled using a GET/POST parameter, or on reply pages where a previously saved malicious message is quoted. After upgrading MyBB to 1.8.24, make sure to update the version attribute in the `codebuttons` template for non-default themes to serve the latest version of the patched `jscripts/bbcodes_sceditor.js` file." } ] }, diff --git a/2020/15xxx/CVE-2020-15701.json b/2020/15xxx/CVE-2020-15701.json index abaae4e7104..fda1611b261 100644 --- a/2020/15xxx/CVE-2020-15701.json +++ b/2020/15xxx/CVE-2020-15701.json @@ -106,6 +106,11 @@ "name": "https://launchpad.net/bugs/1877023", "refsource": "CONFIRM", "url": "https://launchpad.net/bugs/1877023" + }, + { + "refsource": "UBUNTU", + "name": "USN-4449-1", + "url": "https://usn.ubuntu.com/4449-1/" } ] }, @@ -118,4 +123,4 @@ "discovery": "EXTERNAL" }, "work_around": [] -} +} \ No newline at end of file diff --git a/2020/15xxx/CVE-2020-15702.json b/2020/15xxx/CVE-2020-15702.json index 3e83d6ac7ce..95ae011e29a 100644 --- a/2020/15xxx/CVE-2020-15702.json +++ b/2020/15xxx/CVE-2020-15702.json @@ -101,6 +101,11 @@ "name": "https://usn.ubuntu.com/4449-1", "refsource": "CONFIRM", "url": "https://usn.ubuntu.com/4449-1" + }, + { + "refsource": "UBUNTU", + "name": "USN-4449-1", + "url": "https://usn.ubuntu.com/4449-1/" } ] }, @@ -111,4 +116,4 @@ "discovery": "EXTERNAL" }, "work_around": [] -} +} \ No newline at end of file