CVE-2017-8899: XSS
Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has a composite of Stored XSS and Information Disclosure issues in the attachments feature found in User CP. This can be triggered by any Invision Power Board user and can be used to gain access to moderator/admin accounts. The primary cause is the ability to upload an SVG document with a crafted attribute such an onload; however, full path disclosure is required for exploitation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-8899?
CVE-2017-8899 has a high severity rating due to its potential for stored XSS and information disclosure.
How do I fix CVE-2017-8899?
To mitigate CVE-2017-8899, update to the latest version of Invision Power Board beyond 4.1.19.2.
What types of issues are present in CVE-2017-8899?
CVE-2017-8899 contains both Stored XSS and Information Disclosure vulnerabilities.
Who can exploit CVE-2017-8899?
Any user of Invision Power Board could potentially exploit CVE-2017-8899.
What impact does CVE-2017-8899 have on user accounts?
CVE-2017-8899 can be used to gain access to moderator and admin accounts, posing a significant security risk.