CVE-2019-12830 Information
Feb 14, 2021
cve
Description
In MyBB before 1.8.21 an attacker can exploit a parsing flaw in the Private Message / Post renderer that leads to [video] BBCode persistent XSS to take over any forum account aka a nested video MyCode issue.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Reference
https://blog.mybb.com/2019/06/10/mybb-1-8-21-released-security-maintenance-release/ https://blog.ripstech.com/2019/mybb-stored-xss-to-rce/
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
NONE
Base Severity
8.7
Share on: