Exploitation Summary
EIP tracks 1 public exploit for CVE-2018-25132. PoCs published by 0xB9.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in the MyBB Trending Widget Plugin 1.2, where unsanitized thread titles allow arbitrary JavaScript execution when rendered in the widget.
Description
MyBB Trending Widget Plugin 1.2 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through thread titles. Attackers can modify thread titles with script payloads that will execute when other users view the trending widget.
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in the MyBB Trending Widget Plugin 1.2, where unsanitized thread titles allow arbitrary JavaScript execution when rendered in the widget.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N