PT-2021-23436 · Mybb · Mybb

Vz

·

Published

2021-10-26

·

Updated

2024-03-06

·

CVE-2021-41866

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions MyBB versions prior to 1.8.28
Description The issue allows stored XSS because the displayed Template Name value in the Admin CP's theme management is not escaped properly.
Recommendations For versions prior to 1.8.28, update to version 1.8.28 or later to resolve the issue. As a temporary workaround, consider restricting access to the theme management in the Admin CP to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-MYBB-2021-41866
CVE-2021-41866
GHSA-GXHV-R3M5-6QV7

Affected Products

Mybb