Description
Cross-site scripting (XSS) vulnerability in admin/modules/user/users.php in MyBB (aka MyBulletinBoard) 1.6.6 allows remote attackers to inject arbitrary web script or HTML via the conditions[usergroup][] parameter in a search action to admin/index.php.
Remediation
References
Related Vulnerabilities
WeBid Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-3815)
WordPress Plugin Quick Paypal Payments Multiple Vulnerabilities (5.7.25)
WordPress Plugin Events Manager 'events-manager.php' SQL Injection (2.1)
WordPress Plugin No Follow All External Links Spam Injection (2.3.0)