Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-27890

Опубликовано: 14 апр. 2023
Источник: nvd
CVSS3: 5.4
EPSS Низкий

Описание

The Export User plugin through 2.0 for MyBB allows XSS during the process of an admin generating DSGVO data for a user, via the Custom User Title, Location, or Bio field. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:export_user_project:export_user:*:*:*:*:*:mybb:*:*
Версия до 2.0 (включая)

EPSS

Процентиль: 33%
0.00133
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
github
почти 3 года назад

** UNSUPPORTED WHEN ASSIGNED ** The Export User plugin through 2.0 for MyBB allows XSS during the process of an admin generating DSGVO data for a user, via the Custom User Title, Location, or Bio field. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

EPSS

Процентиль: 33%
0.00133
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79