Description
In MyBB before 1.8.21, an attacker can exploit a parsing flaw in the Private Message / Post renderer that leads to [video] BBCode persistent XSS to take over any forum account, aka a nested video MyCode issue.
Remediation
References
Related Vulnerabilities
PHP Other Vulnerability (CVE-2007-1885)
WordPress Plugin WP Google Review Slider Cross-Site Scripting (11.5)
WordPress Plugin Site Offline Or Coming Soon Or Maintenance Mode Security Bypass (1.5.2)
PHP Out-of-bounds Read Vulnerability (CVE-2017-11147)
WordPress Plugin WP Maintenance Mode & Site Under Construction Cross-Site Request Forgery (1.8.2)