CVE-2019-8278: XSS
Published Mar 2, 2019
·Updated
Stored XSS in Invision Power Board versions 3.3.1 - 3.4.8 leads to Remote Code Execution.
Affected Software
1 affected component
Invisioncommunity Invision Power Board>=3.3.1<=3.4.8
Event History
Mar 2, 2019
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2019-8278?
CVE-2019-8278 is a vulnerability that allows for stored XSS in Invision Power Board versions 3.3.1 - 3.4.8, which can lead to Remote Code Execution.
2
How severe is CVE-2019-8278?
CVE-2019-8278 has a severity score of 6.1, which is classified as medium.
3
Which software versions are affected by CVE-2019-8278?
CVE-2019-8278 affects Invision Power Board versions 3.3.1 - 3.4.8.
4
How can CVE-2019-8278 be exploited?
CVE-2019-8278 can be exploited through stored XSS, which allows an attacker to execute remote code on the affected system.
5
Is there a fix for CVE-2019-8278?
To fix CVE-2019-8278, it is recommended to update Invision Power Board to a version beyond 3.4.8, which addresses the vulnerability.