Description
An issue was discovered in inc/class_feedgeneration.php in MyBB 1.8.17. On the forum RSS Syndication page, one can generate a URL such as http://localhost/syndication.php?fid=&type=atom1.0&limit=15. The thread titles (within title elements of the generated XML documents) aren't sanitized, leading to XSS.
Remediation
References
Related Vulnerabilities
MySQL CVE-2021-2002 Vulnerability (CVE-2021-2002)
WebLogic CVE-2024-21182 Vulnerability (CVE-2024-21182)
WordPress Plugin Easy2Map Photos Multiple Vulnerabilities (1.0.9)
WordPress Plugin NextGEN Gallery-WordPress Gallery Local File Inclusion (2.1.56)
MediaWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-35626)