{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2023-46251","assignerOrgId":"a0819718-46f1-4df5-94e2-005712e83aaa","state":"PUBLISHED","assignerShortName":"GitHub_M","dateReserved":"2023-10-19T20:34:00.948Z","datePublished":"2023-11-06T17:41:30.378Z","dateUpdated":"2024-09-04T19:32:41.984Z"},"containers":{"cna":{"title":"Visual editor persistent Cross-site Scripting (XSS) in MyBB","problemTypes":[{"descriptions":[{"cweId":"CWE-79","lang":"en","description":"CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","type":"CWE"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"name":"https://github.com/mybb/mybb/security/advisories/GHSA-wj33-q7vj-9fr8","tags":["x_refsource_CONFIRM"],"url":"https://github.com/mybb/mybb/security/advisories/GHSA-wj33-q7vj-9fr8"},{"name":"https://github.com/mybb/mybb/commit/6dcaf0b4db6254f1833fe8dae295d9ddc2219276","tags":["x_refsource_MISC"],"url":"https://github.com/mybb/mybb/commit/6dcaf0b4db6254f1833fe8dae295d9ddc2219276"},{"name":"https://mybb.com/versions/1.8.37/","tags":["x_refsource_MISC"],"url":"https://mybb.com/versions/1.8.37/"}],"affected":[{"vendor":"mybb","product":"mybb","versions":[{"version":"< 1.8.37","status":"affected"}]}],"providerMetadata":{"orgId":"a0819718-46f1-4df5-94e2-005712e83aaa","shortName":"GitHub_M","dateUpdated":"2023-11-06T17:41:30.378Z"},"descriptions":[{"lang":"en","value":" MyBB is a free and open source forum software. Custom MyCode (BBCode) for the visual editor (_SCEditor_) doesn't escape input properly when rendering HTML, resulting in a DOM-based XSS vulnerability. This weakness can be exploited by pointing a victim to a page where the visual editor is active (e.g. as a post or Private Message) and operates on a maliciously crafted MyCode message. This may occur on pages where message content is pre-filled using a GET/POST parameter, or on reply pages where a previously saved malicious message is quoted. The impact is be mitigated when: 1. the visual editor is disabled globally (_Admin CP → Configuration → Settings → Clickable Smilies and BB Code: [Clickable MyCode Editor](https://github.com/mybb/mybb/blob/mybb_1836/install/resources/settings.xml#L2087-L2094)_ is set to _Off_), or 2. the visual editor is disabled for individual user accounts (_User CP → Your Profile → Edit Options_: _Show the MyCode formatting options on the posting pages_ checkbox is not checked). MyBB 1.8.37 resolves this issue with the commit `6dcaf0b4d`. Users are advised to upgrade. Users unable to upgrade may mitigate the impact without upgrading MyBB by changing the following setting (_Admin CP → Configuration → Settings_):\n- _Clickable Smilies and BB Code → [Clickable MyCode Editor](https://github.com/mybb/mybb/blob/mybb_1836/install/resources/settings.xml#L2087-L2094)_: _Off_. Similarly, individual MyBB forum users are able to disable the visual editor by diabling the account option (_User CP → Your Profile → Edit Options_) _Show the MyCode formatting options on the posting pages_."}],"source":{"advisory":"GHSA-wj33-q7vj-9fr8","discovery":"UNKNOWN"}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T20:37:40.233Z"},"title":"CVE Program Container","references":[{"name":"https://github.com/mybb/mybb/security/advisories/GHSA-wj33-q7vj-9fr8","tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://github.com/mybb/mybb/security/advisories/GHSA-wj33-q7vj-9fr8"},{"name":"https://github.com/mybb/mybb/commit/6dcaf0b4db6254f1833fe8dae295d9ddc2219276","tags":["x_refsource_MISC","x_transferred"],"url":"https://github.com/mybb/mybb/commit/6dcaf0b4db6254f1833fe8dae295d9ddc2219276"},{"name":"https://mybb.com/versions/1.8.37/","tags":["x_refsource_MISC","x_transferred"],"url":"https://mybb.com/versions/1.8.37/"}]},{"affected":[{"vendor":"mybb","product":"mybb","cpes":["cpe:2.3:a:mybb:mybb:*:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"0","status":"affected","lessThan":"1.8.37","versionType":"custom"}]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-09-04T19:26:53.568111Z","id":"CVE-2023-46251","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-09-04T19:32:41.984Z"}}]}}