CVE-2018-25250
HIGHMyBB Last User's Threads in Profile Plugin 1.2 Persistent XSS
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2018-25250. PoCs published by 0xB9.
AI-analyzed exploit summary This exploit demonstrates a persistent XSS vulnerability in MyBB Last User's Threads in Profile Plugin v1.2. The PoC involves creating a thread with a malicious subject containing JavaScript code, which executes when the user profile is viewed.
Description
MyBB Last User's Threads in Profile Plugin 1.2 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts by crafting thread subjects with script tags. Attackers can create threads with script payloads in the subject field that execute when users visit the attacker's profile page.
Exploits (1)
This exploit demonstrates a persistent XSS vulnerability in MyBB Last User's Threads in Profile Plugin v1.2. The PoC involves creating a thread with a malicious subject containing JavaScript code, which executes when the user profile is viewed.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N