Security Advisory

CVE-2018-19201

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2019-03-29 18:58:41
Last updated 2024-08-05 11:30:04
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

A reflected XSS vulnerability in the ModCP Profile Editor in MyBB before 1.8.20 allows remote attackers to inject JavaScript via the 'username' parameter.