An issue was discovered in inc/class_feedgeneration.php in MyBB 1.8.17. On the forum RSS Syndication page, one can generate a URL such as http://localhost/syndication.php?fid=&type=atom1.0&limit=15. The thread titles (within title elements of the generated XML documents) aren't sanitized, leading to XSS.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2018-08-28T19:00:00

Updated: 2024-08-05T10:01:53.370Z

Reserved: 2018-08-20T00:00:00

Link: CVE-2018-15596

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2018-08-28T19:29:16.553

Modified: 2018-11-08T13:19:40.707

Link: CVE-2018-15596

cve-icon Redhat

No data.