Authored by 0xB9

MyBB Favicon plugin version 1.0 suffers from a cross site scripting vulnerability.

# Exploit Title: MyBB [PGM] Favicon Plugin 1.0 – Cross-Site Scripting
# Date: May 2, 2023
# Author: 0xB9
# Twitter: @0xB9sec
# Software Link:
# Version: 1.0
# Tested On: Windows 10


The favicon input in the settings doesn’t sanitize the favicon URL.

Proof of Concept:

– In the admin dashboard go to Configuration > Settings > Favicon
– Enter the following payload in the URL input: “><script>alert(1)</script>.ico
– Visit any page on the forum to trigger the payload