
CVE-2018-25248 MyBB Downloads Plugin 2.0.3 contains a persistent cross-site scripting vulnerability that allows regular members to inject malicious scripts through the download titl… https://www.cve.org/CVERecord?id=CVE-2018-25248
Post summary
The update announces CVE-2018‑25248, a persistent XSS flaw in MyBB Downloads Plugin 2.0.3 that lets regular users inject malicious scripts into download titles.
