Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has pre-auth reflected XSS in the IPS UTF8 Converter v1.1.18: admin/convertutf8/index.php?controller= is the attack vector. This UTF8 Converter vulnerability can easily be used to make a malicious announcement affecting any Invision Power Board user who views the announcement.
Advisories
Source ID Title
EUVD EUVD EUVD-2017-17837 Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has pre-auth reflected XSS in the IPS UTF8 Converter v1.1.18: admin/convertutf8/index.php?controller= is the attack vector. This UTF8 Converter vulnerability can easily be used to make a malicious announcement affecting any Invision Power Board user who views the announcement.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-09-16T23:40:53.814Z

Reserved: 2017-05-11T00:00:00Z

Link: CVE-2017-8897

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2017-05-11T17:29:00.160

Modified: 2025-04-20T01:37:25.860

Link: CVE-2017-8897

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.