CVE-2018-14888

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
14/08/2018
Last modified:
12/10/2018

Description

inc/plugins/thankyoulike.php in the Eldenroot Thank You/Like plugin before 3.1.0 for MyBB allows XSS via a post or thread subject.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:thank_you\/like_project:thank_you\/like:*:*:*:*:*:mybb:*:* 3.1.0 (excluding)