CVE-2024-52702

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
20/11/2024
Last modified:
08/12/2025

Description

A stored cross-site scripting (XSS) vulnerability in the component install\index.php of MyBB v1.8.38 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Website Name parameter. NOTE: this is disputed by the Supplier because Website Name can only be set by an administrator, who may use JavaScript if they wish.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mybb:mybb:1.8.38:*:*:*:*:*:*:*