Description
MyBB Delete Account Plugin 1.4 contains a cross-site scripting vulnerability in the account deletion reason input field. Attackers can inject malicious scripts that will execute in the admin interface when viewing delete account reasons.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
Credits
0xB9
References
www.exploit-db.com/exploits/49500
www.exploit-db.com/exploits/49500 (ExploitDB-49500)
github.com/vintagedaddyo/MyBB_Plugin-Delete_Account/ (MyBB Delete Account Plugin Repository)
www.vulncheck.com/...ete-account-plugin-cross-site-scripting (VulnCheck Advisory: MyBB Delete Account Plugin 1.4 - Cross-Site Scripting)