myBB Forums 1.8.26 Stored Cross-Site Scripting via Forum Announcements
Vulnerability Description
myBB Forums 1.8.26 contains a stored cross-site scripting vulnerability in the forum announcement system that allows authenticated administrators to inject malicious scripts when creating announcements. Attackers can exploit this vulnerability by inserting script payloads in the announcement title field when adding announcements through the 'Forums and Posts' > 'Forum Announcements' interface, causing arbitrary JavaScript to execute when the announcement is displayed on the forum.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-53978
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Andrey Stoykov
References
More from Mybb
View All →Affected Vendor
Mybb
View all reports →