PT-2023-29931 · Sceditor+1 · Sceditor+1

Paulos Yibelo

·

Publicado

2023-11-06

·

Atualizado

2024-03-06

·

CVE-2023-46251

CVSS v3.1

7.5

Alta

VetorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MyBB versions prior to 1.8.37
Description The issue arises from custom MyCode (BBCode) for the visual editor ( SCEditor ) not escaping input properly when rendering HTML, resulting in a DOM-based XSS vulnerability. This weakness can be exploited by pointing a victim to a page where the visual editor is active and operates on a maliciously crafted MyCode message. The impact can occur on pages where message content is pre-filled using a GET/POST parameter, or on reply pages where a previously saved malicious message is quoted.
Recommendations For MyBB versions prior to 1.8.37, upgrade to version 1.8.37 to resolve the issue. As a temporary workaround, consider disabling the visual editor globally by setting Clickable Smilies and BB Code → Clickable MyCode Editor to Off in the Admin CP. Alternatively, individual users can disable the visual editor by unchecking the Show the MyCode formatting options on the posting pages checkbox in their User CP.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BIT-MYBB-2023-46251
CVE-2023-46251
GHSA-WJ33-Q7VJ-9FR8

Produtos afetados

Mybb
Sceditor