CVE-2023-27890

The Export User plugin through 2.0 for MyBB allows XSS during the process of an admin generating DSGVO data for a user, via the Custom User Title, Location, or Bio field. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Configurations

Configuration 1 (hide)

cpe:2.3:a:export_user_project:export_user:*:*:*:*:*:mybb:*:*

History

07 Nov 2023, 04:10

Type Values Removed Values Added
Summary ** UNSUPPORTED WHEN ASSIGNED ** The Export User plugin through 2.0 for MyBB allows XSS during the process of an admin generating DSGVO data for a user, via the Custom User Title, Location, or Bio field. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. The Export User plugin through 2.0 for MyBB allows XSS during the process of an admin generating DSGVO data for a user, via the Custom User Title, Location, or Bio field. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Information

Published : 2023-04-14 01:15

Updated : 2024-08-02 13:15


NVD link : CVE-2023-27890

Mitre link : CVE-2023-27890

CVE.ORG link : CVE-2023-27890


JSON object : View

Products Affected

export_user_project

  • export_user
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')