First published: Thu Feb 14 2019(Updated: )
Stored XSS in Invision Power Board versions 3.3.1 - 3.4.8 leads to Remote Code Execution.
Credit: vulnerability@kaspersky.com vulnerability@kaspersky.com
Affected Software | Affected Version | How to fix |
---|---|---|
Invisioncommunity Invision Power Board | >=3.3.1<=3.4.8 | |
>=3.3.1<=3.4.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-8278 is a vulnerability that allows for stored XSS in Invision Power Board versions 3.3.1 - 3.4.8, which can lead to Remote Code Execution.
CVE-2019-8278 has a severity score of 6.1, which is classified as medium.
CVE-2019-8278 affects Invision Power Board versions 3.3.1 - 3.4.8.
CVE-2019-8278 can be exploited through stored XSS, which allows an attacker to execute remote code on the affected system.
To fix CVE-2019-8278, it is recommended to update Invision Power Board to a version beyond 3.4.8, which addresses the vulnerability.