Lucene search

K
vulnrichmentMitreVULNRICHMENT:CVE-2023-27890
HistoryApr 14, 2023 - 12:00 a.m.

CVE-2023-27890

2023-04-1400:00:00
mitre
github.com
2
mybb
export user
xss
vulnerability
dsgvo
admin
user data

AI Score

6.1

Confidence

High

EPSS

0.002

Percentile

55.8%

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

The Export User plugin through 2.0 for MyBB allows XSS during the process of an admin generating DSGVO data for a user, via the Custom User Title, Location, or Bio field. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

AI Score

6.1

Confidence

High

EPSS

0.002

Percentile

55.8%

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

Related for VULNRICHMENT:CVE-2023-27890