Exploitation Summary
EIP tracks 1 public exploit for CVE-2018-10365. PoCs published by 0xB9.
AI-analyzed exploit summary This exploit demonstrates a persistent XSS vulnerability in the MyBB Threads to Link Plugin v1.3. The attack involves injecting malicious JavaScript into the Thread Link field during thread editing, which executes when the thread is viewed.
Description
An XSS issue was discovered in the Threads to Link plugin 1.3 for MyBB. When editing a thread, the user is given the option to convert the thread to a link. The thread link input box is not properly sanitized.
Exploits (1)
This exploit demonstrates a persistent XSS vulnerability in the MyBB Threads to Link Plugin v1.3. The attack involves injecting malicious JavaScript into the Thread Link field during thread editing, which executes when the thread is viewed.
References (1)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N