CVE-2017-8898: XSS
Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has stored XSS in the Announcements, allowing privilege escalation from an Invision Power Board moderator to an admin. An attack uses the announcecontent parameter in an index.php?/modcp/announcements/&action=create request. This is related to the "<> Source" option.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-8898?
CVE-2017-8898 is classified as a medium severity vulnerability due to the potential for privilege escalation.
How do I fix CVE-2017-8898?
To fix CVE-2017-8898, upgrade your Invision Power Board to version 4.1.19.3 or later.
What are the consequences of exploiting CVE-2017-8898?
Exploiting CVE-2017-8898 allows a moderator to gain admin privileges unauthorizedly.
Which versions are affected by CVE-2017-8898?
CVE-2017-8898 affects Invision Power Services Community Suite versions 4.1.19.2 and earlier.
What type of vulnerability is CVE-2017-8898?
CVE-2017-8898 is a stored cross-site scripting (XSS) vulnerability.