MyBB 1.8.15, when accessed with Microsoft Edge, mishandles 'target="_blank" rel="noopener"' in A elements, which makes it easier for remote attackers to conduct redirection attacks.
No PoCs from references.
- https://github.com/0xT11/CVE-POC
- https://github.com/hbranco/CVE-2018-10678