First published: Thu May 11 2017(Updated: )
Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has stored XSS in the Announcements, allowing privilege escalation from an Invision Power Board moderator to an admin. An attack uses the announce_content parameter in an index.php?/modcp/announcements/&action=create request. This is related to the "<> Source" option.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Invision Community | <=4.1.19.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8898 is classified as a medium severity vulnerability due to the potential for privilege escalation.
To fix CVE-2017-8898, upgrade your Invision Power Board to version 4.1.19.3 or later.
Exploiting CVE-2017-8898 allows a moderator to gain admin privileges unauthorizedly.
CVE-2017-8898 affects Invision Power Services Community Suite versions 4.1.19.2 and earlier.
CVE-2017-8898 is a stored cross-site scripting (XSS) vulnerability.