CVE-2018-10678

Severity CVSS v4.0:
Pending analysis
Type:
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
Publication date:
13/05/2018
Last modified:
05/06/2018

Description

MyBB 1.8.15, when accessed with Microsoft Edge, mishandles 'target="_blank" rel="noopener"' in A elements, which makes it easier for remote attackers to conduct redirection attacks.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mybb:mybb:1.8.15:*:*:*:*:*:*:*