VYPR
Unrated severityNVD Advisory· Published Dec 30, 2010· Updated Apr 29, 2026

CVE-2010-4522

CVE-2010-4522

Description

Multiple cross-site scripting (XSS) vulnerabilities in MyBB (aka MyBulletinBoard) 1.4.14, and 1.6.x before 1.6.1, allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) editpost.php, (2) member.php, and (3) newreply.php.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Multiple cross-site scripting vulnerabilities in MyBB 1.4.14 and 1.6.x before 1.6.1 allow remote attackers to inject arbitrary web script or HTML via editpost.php, member.php, and newreply.php.

Vulnerability

Multiple cross-site scripting (XSS) vulnerabilities exist in MyBB versions 1.4.14 and 1.6.x prior to 1.6.1. The flaws are present in the editpost.php, member.php, and newreply.php scripts, where user-supplied input is not properly sanitized before being reflected in output [1]. This allows an attacker to inject arbitrary HTML or JavaScript.

Exploitation

An attacker can exploit these vulnerabilities by crafting a malicious URL or form submission that includes script code in parameters processed by the affected scripts. No authentication is required; the attacker only needs to trick a victim into visiting the crafted link or submitting the form. The injected script executes in the victim's browser within the context of the MyBB application.

Impact

Successful exploitation enables an attacker to execute arbitrary web script or HTML in the victim's browser. This can lead to session hijacking, defacement of forum content, theft of sensitive information, or other actions performed as the victim user.

Mitigation

MyBB released version 1.6.1 on December 15, 2010, which fixes these vulnerabilities [1]. Users running MyBB 1.4.14 can apply a security patch provided in the same announcement. All users are advised to upgrade to the latest patched version. No workarounds are documented.

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3
  • MyBB/Mybb3 versions
    cpe:2.3:a:mybb:mybb:1.4.14:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:mybb:mybb:1.4.14:*:*:*:*:*:*:*
    • cpe:2.3:a:mybb:mybb:1.6.0:*:*:*:*:*:*:*
    • (no CPE)range: 1.4.14, <1.6.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.