myBB Forums 1.8.26 Stored Cross-Site Scripting via Template Management
Vulnerability Description
myBB Forums 1.8.26 contains a stored cross-site scripting vulnerability in the template management system that allows authenticated administrators to inject malicious scripts when creating new templates. Attackers can exploit this vulnerability by inserting script payloads in the template title field when adding new templates through the 'Templates and Style' > 'Templates' > 'Manage Templates' > 'Global Templates' interface, causing arbitrary JavaScript to execute when the template is viewed.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-53976
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Andrey Stoykov
References
More from Mybb
View All →Affected Vendor
Mybb
View all reports →