SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-15596

The thread titles (within title elements of the generated XML documents) aren't sanitized, leading to XSS.

MEDIUM 6.1EPSS 2.26%

Does this matter?

Lower severity and a low EPSS score (2.26%). Track it; it rarely justifies an emergency change on its own.

Description

An issue was discovered in inc/class_feedgeneration.php in MyBB 1.8.17. On the forum RSS Syndication page, one can generate a URL such as http://localhost/syndication.php?fid=&type=atom1.0&limit=15. The thread titles (within title elements of the generated XML documents) aren't sanitized, leading to XSS.

CVSS 3.0
6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
2.26% probability · 82th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
mybb/mybb
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.