The "Latest Posts on Profile" plugin 1.1 for MyBB has XSS because there is an added section in a user profile that displays that user's most recent posts without sanitizing the tsubject (aka thread subject) field.
Advisories
Source ID Title
EUVD EUVD EUVD-2018-2652 The "Latest Posts on Profile" plugin 1.1 for MyBB has XSS because there is an added section in a user profile that displays that user's most recent posts without sanitizing the tsubject (aka thread subject) field.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T07:39:07.723Z

Reserved: 2018-04-30T00:00:00

Link: CVE-2018-10580

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-05-11T14:29:00.203

Modified: 2024-11-21T03:41:36.110

Link: CVE-2018-10580

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.