Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site scripting (XSS) vulnerability in action_admin/member.php in Invision Power Board (IPB) 2.1.7 and earlier allows remote authenticated users to inject arbitrary web script or HTML via a reference to a script in the avatar setting, which can be leveraged for a cross-site request forgery (CSRF) attack involving forced SQL execution by an admin.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Invision Power Board 'member.php'跨站脚本攻击漏洞
Vulnerability Description
Invision Power Board (IPB) 2.1.7和之前的版本,其action_admin/member.php中的跨站脚本攻击漏洞,远程认证用户可以通过对avatar设置中脚本的引用来注入任意的Web脚本或HTML,从而可以被包含有由管理员强制的SQL执行的跨站请求伪造攻击利用。
CVSS Information
N/A
Vulnerability Type
N/A