← Zurück zur CVE-Suche

CVE-2018-25249

MyBB My Arcade Plugin

Beschreibung

MyBB My Arcade Plugin 1.3 contains a persistent cross-site scripting vulnerability that allows authenticated users to inject malicious scripts through arcade game score comments. Attackers can add crafted HTML and JavaScript payloads in the comment field that execute when other users view or edit the comment.

CVSS 6.4EPSS 0.254%Risiko 0.65
Quelle öffnen
Veröffentlicht
2026-04-04 14:16:20
Betroffene Versionen
==1.3
Typ
Package
Zuletzt geändert
2026-07-21 07:10:00
Vektor
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N