Exploitation Summary
EIP tracks 1 public exploit for CVE-2018-10580. PoCs published by 0xB9.
AI-analyzed exploit summary This exploit demonstrates a persistent XSS vulnerability in the MyBB Latest Posts on Profile Plugin v1.1. The PoC involves creating a thread with a malicious script in the subject, which executes when viewing the user's profile.
Description
The "Latest Posts on Profile" plugin 1.1 for MyBB has XSS because there is an added section in a user profile that displays that user's most recent posts without sanitizing the tsubject (aka thread subject) field.
Exploits (1)
This exploit demonstrates a persistent XSS vulnerability in the MyBB Latest Posts on Profile Plugin v1.1. The PoC involves creating a thread with a malicious script in the subject, which executes when viewing the user's profile.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N