CVE-2024-52702
MEDIUMMybb - XSS
Title source: ruleDescription
A stored cross-site scripting (XSS) vulnerability in the component install\index.php of MyBB v1.8.38 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Website Name parameter. NOTE: this is disputed by the Supplier because Website Name can only be set by an administrator, who may use JavaScript if they wish.
Scores
CVSS v3
5.4
EPSS
0.0057
EPSS Percentile
68.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Classification
CWE
CWE-79
Status
published
Affected Products (1)
mybb/mybb
Timeline
Published
Nov 20, 2024
Tracked Since
Feb 18, 2026