CVE-2019-9650
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 3.4%
from disclosure to weapon8 days
Published on NVDMar 11
1st PoC+8d
exploitation probability
3.4%top 12% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
An XSS issue was discovered in upcoming_events.php in the Upcoming Events plugin before 1.33 for MyBB via a crafted name for an event.
Affected products
n/a · n/apublic PoCs found — 3
cve_referencepacketstormsecurity.com/files/152152/MyBB-Upcoming-Events-1.32-Cross-Site-Scripting.htmlunverifiedcve_referencewww.exploit-db.com/exploits/46558/unverifiedexploitdbwww.exploit-db.com/exploits/46558unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://packetstormsecurity.com/files/152152/MyBB-Upcoming-Events-1.32-Cross-Site-Scripting.htmlhttps://community.mybb.com/mods.php?action=changelog&pid=1231https://github.com/vintagedaddyo/MyBB_Plugin-Upcoming_Events/pull/1/commits/d0a0e1c6e56f248613e0150344ebea8764bba5fahttps://www.exploit-db.com/exploits/46558/