Vulnerability Description
MyBB Trending Widget Plugin 1.2 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through thread titles. Attackers can modify thread titles with script payloads that will execute when other users view the trending widget.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mybb | Trending Widget | 1.2 |
Related Weaknesses (CWE)
References
- https://github.com/zainali99/trends-widgetProduct
- https://www.exploit-db.com/exploits/49504ExploitVDB Entry
- https://www.vulncheck.com/advisories/mybb-trending-widget-plugin-cross-site-scriThird Party Advisory
FAQ
What is CVE-2018-25132?
CVE-2018-25132 is a vulnerability with a CVSS score of 6.1 (MEDIUM). MyBB Trending Widget Plugin 1.2 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through thread titles. Attackers can modify thread titles with script pa...
How severe is CVE-2018-25132?
CVE-2018-25132 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-25132?
Check the references section above for vendor advisories and patch information. Affected products include: Mybb Trending Widget.