CVE-2018-25116
Last modified
CVE-2018-25116 is a medium-severity vulnerability rated 5.1/10 on the CVSS scale. MyBB Thread Redirect Plugin 0.2.1 contains a cross-site scripting vulnerability in the custom text input field for thread redirects. Attackers can inject malicious SVG scripts that will execute when other users view the thread, allowing arbitrary script execution.. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
MyBB Thread Redirect Plugin 0.2.1 contains a cross-site scripting vulnerability in the custom text input field for thread redirects. Attackers can inject malicious SVG scripts that will execute when other users view the thread, allowing arbitrary script execution.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mybb | Thread Redirect | 0.2.1 |
References
- https://www.exploit-db.com/exploits/49505Exploit, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2018-25116?
How severe is CVE-2018-25116?
How do I fix CVE-2018-25116?
Are you affected by CVE-2018-25116?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
