PT-2021-17383 · Mybb · Mybb

Igor Sak-Sakovskiy

·

Published

2021-02-22

·

Updated

2024-03-06

·

CVE-2021-27279

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions MyBB versions prior to 1.8.25
Description The issue allows stored XSS via nested [email] tags with MyCode (aka BBCode).
Recommendations For versions prior to 1.8.25, update to version 1.8.25 or later to resolve the issue.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-MYBB-2021-27279
CVE-2021-27279
GHSA-6483-HCPP-P75W

Affected Products

Mybb