Intelligence View
⚡ tsecurity.de Intelligence
CVE-2018-25249 | My Arcade Plugin 1.3 on MyBB Comment cross site scripting (Exploit 44186 / EUVD-2018-21751)
A vulnerability, which was classified as problematic, was found in My Arcade Plugin 1.3 on MyBB. Affected by this issue is some unknown functionality.…
A vulnerability, which was classified as problematic, was found in My Arcade Plugin 1.3 on MyBB. Affected by this issue is some unknown functionality. Executing a manipulation of the argument Comment can lead to cross site scripting.
This vulnerability appears as CVE-2018-25249. The attack may be performed from remote. In addition, an exploit is available.
This vulnerability appears as CVE-2018-25249. The attack may be performed from remote. In addition, an exploit is available.
Cyber Threat Intelligence & Forensik
ATT&CK-Navigator · IoC-Radar · Exploit-Belege
Compliance, SLA & Vendor Adherence
Advisory-Prüfung · Score-Einordnung · Fristen
CISA-SSVC-Triage (vulnrichment)CVE-2018-25249
Exploitation: poc (PoC verfügbar)Automatable: no (Nicht automatisierbar)Technical Impact: partial (Teilweise)
Quelle: CISA-ADP vulnrichment · Stand 2026-04-06T13:26:59.952278Z · CISA Coordinator
Advisory Radar
Workaround & Virtual-Patching empfohlen
Hersteller-Sicherheitsmeldungen & Patch-Status
Handlungsempfehlung für Administratoren
Öffentliche PoCs existieren. Isolieren Sie das System oder wenden Sie Micro-Segmentierungsregeln an, bis offizielle Patches vorliegen.
Referenzen aus der Primärquelle („Verifiziert" nur bei Hersteller-Domäne):
-
Web Referencecommunity.mybb.com
2 öffentliche Exploit-Referenz(en) detektiert (Exploit Database (EDB)).
PoC einsehen