Vulnerability Description
MyBB before 1.8.28 allows stored XSS because the displayed Template Name value in the Admin CP's theme management is not escaped properly.
CVSS Score
5.4
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mybb | Mybb | < 1.8.28 |
Related Weaknesses (CWE)
References
- https://github.com/mybb/mybb/security/advisories/Third Party Advisory
- https://github.com/mybb/mybb/security/advisories/GHSA-gxhv-r3m5-6qv7PatchThird Party Advisory
- https://github.com/mybb/mybb/security/advisories/Third Party Advisory
- https://github.com/mybb/mybb/security/advisories/GHSA-gxhv-r3m5-6qv7PatchThird Party Advisory
FAQ
What is CVE-2021-41866?
CVE-2021-41866 is a vulnerability with a CVSS score of 5.4 (MEDIUM). MyBB before 1.8.28 allows stored XSS because the displayed Template Name value in the Admin CP's theme management is not escaped properly.
How severe is CVE-2021-41866?
CVE-2021-41866 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-41866?
Check the references section above for vendor advisories and patch information. Affected products include: Mybb Mybb.