vendor:
IP.Board
by:
Mehdi Alouache
8,8
CVSS
HIGH
Persistent XSS
79
CWE
Product Name: IP.Board
Affected Version From: 4.1.4.x
Affected Version To: 4.1.4.x
Patch Exists: YES
Related CWE: N/A
CPE: a:invision_power_services:ip.board
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2015
IP.Board Persistent XSS Vulnerability
Any registered user can execute remote javascript code by sending a private message to another user. The malicious JS code has to be written in the title of the message, and the receiver must have enabled the notifications when a new message is delivered. Note that the code will be directly executed as soon as the notification appear. (The receiver doesn't even need to check his inbox).
Mitigation:
Patch the vulnerability with the (incoming) associated patch.