PoC Index

CVE-2018-6506

MEDIUM 4.8EPSS 0.5%

Cross-Site Scripting (XSS) exists in the Add Forum feature in the Administrative Panel in miniBB 3.2.2 via crafted use of an onload attribute of an SVG element in the supertitle field.

CVSS v3.0
4.8 MEDIUMCVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
CVSS v2.0
3.5 LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
EPSS
0.53% chance of exploitation in the next 30 days, 43th percentile
Published
2018-02-12
Updated
2024-08-05

Proof-of-concept exploits (1)

References

Related