Security Advisory

CVE-2024-52702

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2024-11-20 00:00:00
Last updated 2025-12-08 16:03:55
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

A stored cross-site scripting (XSS) vulnerability in the component install\index.php of MyBB v1.8.38 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Website Name parameter. NOTE: this is disputed by the Supplier because Website Name can only be set by an administrator, who may use JavaScript if they wish.