First published: Thu May 11 2017(Updated: )
Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has stored XSS in the Announcements, allowing privilege escalation from an Invision Power Board moderator to an admin. An attack uses the announce_content parameter in an index.php?/modcp/announcements/&action=create request. This is related to the "<> Source" option.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Invisioncommunity Invision Power Board | <=4.1.19.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.