# Exploit Title: MyBB Delete Account Plugin 1.4 - Cross-Site Scripting# Date: 1/25/2021# Author: 0xB9# Twitter: @0xB9Sec# Contact: 0xB9[at]pm.me# Software Link: https://github.com/vintagedaddyo/MyBB_Plugin-Delete_Account/# Version: 1.4# Tested on: Windows 101. Description:
This plugin allows users to delete their account. Giving a reason for deleting your account is vulnerable to XSS.2. Proof of Concept:- Go to User CP -> Delete Account
- Input a payload for delete account reason <script>alert('XSS')</script>
Payload will execute here.. admin/index.php?module=user-deleteaccount