CVE-2021-39249 | Invision Community (IPS) before 4.6.5.1 allows reflected XSS

XMAN

Active member
Joined
Jul 12, 2021
Messages
19,642
Reaction score
71
Points
38
CVE-2021-39249 Invision Community (aka IPS Community Suite or IP-Board) before 4.6.5.1 allows reflected XSS because the filenames of uploaded files become predictable through a brute-force attack against the PHP mt_rand function.


Date Record Created
Assigning CNA
References
Description
Invision Community (aka IPS Community Suite or IP-Board) before 4.6.5.1 allows reflected XSS because the filenames of uploaded files become predictable through a brute-force attack against the PHP mt_rand function.
Note: References are provided for the convenience of the reader to help distinguish between vulnerabilities. The list is not intended to be complete.
MITRE Corporation
20210817Disclaimer: The record

Continue reading...
 
Top