Description
Cross-site scripting (XSS) vulnerability in the redirect function in functions.php in MyBB (aka MyBulletinBoard) 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the url parameter in a removesubscriptions action to moderation.php, related to use of the ajax option to request a JavaScript redirect. NOTE: this can be leveraged to execute PHP code and bypass cross-site request forgery (CSRF) protection.
Remediation
References
Related Vulnerabilities
WordPress Plugin Appointment Calendar Multiple Cross-Site Scripting Vulnerabilities (2.7.4)
MySQL CVE-2016-5629 Vulnerability (CVE-2016-5629)
WordPress Plugin Complianz-GDPR/CCPA Cookie Consent Cross-Site Scripting (5.5.2)
WordPress Plugin Albo Pretorio On line Multiple Vulnerabilities (3.2)
Apache Tomcat Incorrect Authorization Vulnerability (CVE-2016-6797)