This is a writeup describing two stored XSS vulnerabilities in LayerBB 1.1.2, affecting polls and custom profile fields. The PoC demonstrates how arbitrary JavaScript can be executed when users view a thread or profile.
Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target:LayerBB 1.1.2
Auth required
Prerequisites:Access to create a thread or edit profile fields