Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

MyBB 1.8.2 'usercp.php' HTML Injection Vulnerability

High

Synopsis

The remote web server is running a PHP application which is outdated and thus prone to an HTML injection vulnerability.

Description

The remote web server hosts MyBulletinBoard, a web-based discussion board application.

MyBB version 1.8.2 is prone to an HTML-injection vulnerability; other versions may also be affected. This is because it fails to sufficiently sanitize user-supplied input submitted to the 'usertitle' post parameter of the 'usercp.php' script. Attacker-supplied HTML or JavaScript code could run in the context of the affected site, compromising its contents or granting unauthorized access.

Solution

Upgrade to MyBB version 1.8.3 or higher.