An attacker can exploit these vulnerabilities to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, disclose or modify sensitive information, or perform unauthorized actions. Other attacks are also possible.
Versions prior to MyBB 1.6.6 are vulnerable.
Vendor Status:
MyBB as issued an update for this vulnerablity