Vulnerability Description
MyBB Like Plugin 3.0.0 contains a stored cross-site scripting vulnerability. Authenticated attackers can inject script payloads into post or thread subjects; when other users view a profile that displays the attacker's liked posts, the unsanitized subject is rendered, executing the script in the viewer's browser.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mybb | Thankyou\/Like System | <= 3.0.0 |
Related Weaknesses (CWE)
References
- https://community.mybb.com/mods.php?action=view&pid=360Product
- https://www.exploit-db.com/exploits/45179ExploitVDB Entry
- https://www.vulncheck.com/advisories/mybb-like-plugin-cross-site-scripting-via-uThird Party Advisory
FAQ
What is CVE-2018-25247?
CVE-2018-25247 is a vulnerability with a CVSS score of 6.1 (MEDIUM). MyBB Like Plugin 3.0.0 contains a stored cross-site scripting vulnerability. Authenticated attackers can inject script payloads into post or thread subjects; when other users view a profile that displ...
How severe is CVE-2018-25247?
CVE-2018-25247 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-25247?
Check the references section above for vendor advisories and patch information. Affected products include: Mybb Thankyou\/Like System.