Vulnerability Description
Cross Site Scripting vulnerability in Mybb Mybb Forums v.1.8.33 allows a local attacker to execute arbitrary code via the theme Name parameter in the theme management component.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mybb | Mybb | < 1.8.37 |
Related Weaknesses (CWE)
References
- https://github.com/Or4ngm4n/Mybb/blob/main/MyBB%201.8.33%20Cross%20Site%20ScriptExploit
- https://github.com/mybb/mybb/security/advisories/GHSA-4xqm-3cm2-5xgfPatchThird Party Advisory
- https://raw.githubusercontent.com/Or4ngm4n/Mybb/main/Screenshot%202023-10-08%200Product
- https://github.com/Or4ngm4n/Mybb/blob/main/MyBB%201.8.33%20Cross%20Site%20ScriptExploit
- https://github.com/mybb/mybb/security/advisories/GHSA-4xqm-3cm2-5xgfPatchThird Party Advisory
- https://raw.githubusercontent.com/Or4ngm4n/Mybb/main/Screenshot%202023-10-08%200Product
FAQ
What is CVE-2023-45556?
CVE-2023-45556 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Cross Site Scripting vulnerability in Mybb Mybb Forums v.1.8.33 allows a local attacker to execute arbitrary code via the theme Name parameter in the theme management component.
How severe is CVE-2023-45556?
CVE-2023-45556 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-45556?
Check the references section above for vendor advisories and patch information. Affected products include: Mybb Mybb.