{"api_version":"1","generated_at":"2026-07-23T07:34:12+00:00","cve":"CVE-2015-4552","urls":{"html":"https://cve.report/CVE-2015-4552","api":"https://cve.report/api/cve/CVE-2015-4552.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-4552","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-4552"},"summary":{"title":"CVE-2015-4552","description":"Cross-site scripting (XSS) vulnerability in the quick edit function in xmlhttp.php in MyBB (aka MyBulletinBoard) before 1.8.5 allows remote attackers to inject arbitrary web script or HTML via the content of a post.","state":"PUBLISHED","assigner":"mitre","published_at":"2015-09-03 17:59:01","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://adrianhayter.com/exploits.php","name":"http://adrianhayter.com/exploits.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Adrian Hayter - Exploits","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://blog.mybb.com/2015/05/27/mybb-1-8-5-1-6-17-merge-system-1-8-5-release/","name":"http://blog.mybb.com/2015/05/27/mybb-1-8-5-1-6-17-merge-system-1-8-5-release/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"MyBB 1.8.5, 1.6.17 & Merge System 1.8.5 Release | MyBB Blog","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1033471","name":"http://www.securitytracker.com/id/1033471","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"MyBB Bugs Permit Cross-Site Scripting, Cross-Site Request Forgery, and Email Address Spoofing Attacks - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-4552","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-4552","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"4552","vulnerable":"1","versionEndIncluding":"1.8.4","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mybb","cpe5":"mybb","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T06:18:12.065Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"1033471","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1033471"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://adrianhayter.com/exploits.php"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://blog.mybb.com/2015/05/27/mybb-1-8-5-1-6-17-merge-system-1-8-5-release/"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2015-05-27T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in the quick edit function in xmlhttp.php in MyBB (aka MyBulletinBoard) before 1.8.5 allows remote attackers to inject arbitrary web script or HTML via the content of a post."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-12-20T16:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"1033471","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1033471"},{"tags":["x_refsource_MISC"],"url":"http://adrianhayter.com/exploits.php"},{"tags":["x_refsource_CONFIRM"],"url":"http://blog.mybb.com/2015/05/27/mybb-1-8-5-1-6-17-merge-system-1-8-5-release/"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2015-4552","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in the quick edit function in xmlhttp.php in MyBB (aka MyBulletinBoard) before 1.8.5 allows remote attackers to inject arbitrary web script or HTML via the content of a post."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"1033471","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1033471"},{"name":"http://adrianhayter.com/exploits.php","refsource":"MISC","url":"http://adrianhayter.com/exploits.php"},{"name":"http://blog.mybb.com/2015/05/27/mybb-1-8-5-1-6-17-merge-system-1-8-5-release/","refsource":"CONFIRM","url":"http://blog.mybb.com/2015/05/27/mybb-1-8-5-1-6-17-merge-system-1-8-5-release/"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2015-4552","datePublished":"2015-09-03T17:00:00.000Z","dateReserved":"2015-06-14T00:00:00.000Z","dateUpdated":"2024-08-06T06:18:12.065Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2015-09-03 17:59:01","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mybb:mybb:*:*:*:*:*:*:*:*","versionEndIncluding":"1.8.4","matchCriteriaId":"171A772D-0FDB-4ADD-A4C4-C8E849D8B255"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"4552","Ordinal":"1","Title":"CVE-2015-4552","CVE":"CVE-2015-4552","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"4552","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in the quick edit function in xmlhttp.php in MyBB (aka MyBulletinBoard) before 1.8.5 allows remote attackers to inject arbitrary web script or HTML via the content of a post.","Type":"Description","Title":"CVE-2015-4552"},{"CveYear":"2015","CveId":"4552","Ordinal":"2","NoteData":"2015-09-03","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"4552","Ordinal":"3","NoteData":"2016-12-20","Type":"Other","Title":"Modified"}]}}}