MyBB External Redirect Warning 1.3 Cross Site Scripting ≈ Packet Storm

MyBB External Redirect Warning 1.3 Cross Site Scripting ≈ Packet Storm

Home[1] Files[2] News[3] &[SERVICES_TAB] Contact[4] Add New[5]

MyBB External Redirect Warning 1.3 Cross Site Scripting[6]
Authored by 0xB9[7]

MyBB External Redirect Warning plugin version 1.3 suffers from a cross site scripting vulnerability.

advisories | CVE-2022-28353[8]
SHA-256 | 30648b0a86ff796492c571bdf536801d2869613474a695f71e4142c2ef8f81e5

Change Mirror[12] Download[13]

        # Exploit Title: MyBB External Redirect Warning Plugin 1.3 – Cross-Site Scripting
# Date: February 1, 2021
# Author: 0xB9
# Twitter: @0xB9sec
# Software Link: https://community.mybb.com/mods.php?action=view&pid=493
# Version: 1.3
# Tested On: Windows 10
# CVE: CVE-2022-28353
Description:
This plugin notifies the user when they are being redirect to an off-site page. The redirect URL is vulnerable to XSS.
Proof of Concept:
– Go to the following URL… external.php?url=javascript:alert(1);
– Click continue
Payload will execute

Login[14] or Register[15] to add favorites

File Archive:

March 2023

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa

File Tags

File Archives

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services[120]
Hosting By
Rokasec[121]
close
Image

Pensée du jour :

Ce que l'homme a fait ,

l'homme peut le défaire.

 

"No secure path in the world"