Description
Cross-site scripting (XSS) vulnerability in the redirect function in functions.php in MyBB (aka MyBulletinBoard) 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the url parameter in a removesubscriptions action to moderation.php, related to use of the ajax option to request a JavaScript redirect. NOTE: this can be leveraged to execute PHP code and bypass cross-site request forgery (CSRF) protection.
Remediation
References
Related Vulnerabilities
PostgreSQL Numeric Errors Vulnerability (CVE-2007-4769)
OpenSSL Use of a Broken or Risky Cryptographic Algorithm Vulnerability (CVE-2021-23839)
Drupal Core Remote Code Execution (8.0.0 - 9.2.21)
Oracle Application Server CVE-2008-0345 Vulnerability (CVE-2008-0345)
WordPress Plugin Featured Comments Cross-Site Request Forgery (1.2.1)