MyBB Timeline Plugin 1.0 Cross-Site Scripting and CSRF
Vulnerability Description
MyBB Timeline Plugin 1.0 contains cross-site scripting vulnerabilities that allow attackers to inject malicious scripts through thread titles, post content, and user profile fields like Location and Bio. Attackers can also exploit a cross-site request forgery vulnerability in the timeline.php profile action to change a user's cover picture by crafting malicious forms that execute when victims visit affected profiles.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-47934
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- 0xB9
References
More from MyBB
View All →Affected Vendor
MyBB
View all reports →