Skip to content

Custom moderator tools reflected XSS

Low
dvz published GHSA-cmmr-39v8-8rx2 Mar 10, 2021

Package

MyBB

Affected versions

< 1.8.26

Patched versions

1.8.26

Description

Impact

User input attached to CSRF token-protected POST requests, inserted into hidden form fields on custom Moderator Tools action confirmation pages, is not properly sanitized, leading to a reflected XSS vulnerability.

Indirect controls, including the anti-CSRF token, and the SameSite Cookie Flag (enabled by default) reduce the likelihood of successful exploitation.

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L

Patches

MyBB 1.8.26 resolves this issue with the following changes:

References

For more information

Go to mybb.com/security to report possible security concerns or to learn more about security research at MyBB.

Contact

The security team can be reached at security@mybb.com.

Severity

Low

CVE ID

CVE-2021-27949

Weaknesses