Impact
The vulnerability is in MyBB's Contact module before version 1.8.40. It accepts a redirect target from the HTTP 'from' parameter or the Referer header without validating the URL scheme or path. An attacker can supply a javascript: URI, which becomes the target of a link displayed on the page. When a user clicks the link, the supplied JavaScript runs in their browser, allowing reflected XSS.
Affected Systems
All installations of MyBB forum software running a version earlier than 1.8.40 are affected. This includes community‑hosted and self‑hosted deployments that have not applied the 1.8.40 release, which contains the fix. No other vendors or products are listed as affected.
Risk and Exploitability
The CVSS score of 9.3 reflects a high‑severity client‑side flaw. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The attack can be triggered remotely via a crafted link without authentication, and the reflected JavaScript executes in the victim’s browser. The impact is therefore limited to the user’s session when the attack link is followed.
OpenCVE Enrichment