Back to Database
Status published
Medium
CVE-2018-6506
Cross-Site Scripting (XSS) exists in the Add Forum feature in...
Vulnerability Description
Cross-Site Scripting (XSS) exists in the Add Forum feature in the Administrative Panel in miniBB 3.2.2 via crafted use of an onload attribute of an SVG element in the supertitle field.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-6506
Credits & Attribution
No credits recorded in the NVD database.
More from minibb
View All →CVE-2014-9254
bb_func_unsub.php in MiniBB 3.1 before 20141127 uses an incorrect regular...
High
7.5
CVE-2013-5020
Multiple cross-site scripting (XSS) vulnerabilities in bb_admin.php in MiniBB before...
Medium
4.3
CVE-2008-2067
SQL injection vulnerability in bb_admin.php in miniBB 2.2a allows remote...
High
7.5
CVE-2008-2066
Cross-site scripting (XSS) vulnerability in bb_admin.php in miniBB 2.2a allows...
Medium
4.3
CVE-2008-2029
Multiple SQL injection vulnerabilities in (1) setup_mysql.php and (2) setup_options.php...
Medium
6.8
Affected Vendor
minibb
View all reports →Affected Software
minibb
Vulnerable Versions:
3.2.2
Timeline
Official Publish:
February 12th, 2018
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.