CVE-2018-14724

MEDIUM

MyBB 1.0 - XSS

Title source: llm
STIX 2.1

Description

In the Ban List plugin 1.0 for MyBB, any forum user with mod privileges can ban users and input an XSS payload into the ban reason, which is executed on the bans.php page.

Exploits (1)

exploitdb WORKING POC
by 0xB9 · textwebappsphp
https://www.exploit-db.com/exploits/46347

References (1)

Core 1
Core References
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/46347

Scores

CVSS v3 5.4
EPSS 0.0019
EPSS Percentile 40.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
mybb/ban_list 1.0
Published Mar 21, 2019
Tracked Since Feb 18, 2026