MyBB Plugin Downloads 2.0.3 - Cross-Site Scripting

EDB-ID: 44400
Author: 0xB9
Published: 2018-04-05
Type: Webapps
Platform: PHP
Vulnerable App: N/A

 # Date: 3/28/18 
# Author: 0xB9
# Contact: or 0xB9[at]
# Software Link:
# Version: 2.0.3
# Tested on: Ubuntu 17.10

1. Description:
It is a plugin which adds a page to download files. If enabled, regular members can add new downloads to the page after admin approval.

2. Proof of Concept:

Persistent XSS
- Go to downloads.php page
- Create a New Download
- Add the following to the title <BODY ONLOAD=alert('XSS')>
- Now when the admin goes to validate your download he will be alerted

3. Solution:
Update to the latest release


Related Posts