Description
|
|
Multiple vulnerabilities have been identified in Invision Power Board (IPB), which could be exploited by malicious users to execute arbitrary scripting code or by malicious moderators to bypass security restrictions.
The first vulnerability is due to input validation errors in the "lib/func_usercp.php" and "classes/bbcode/class_bbcode_core.php" scripts that fail to properly validate the "url_photo", "url_avatar" and "url" variables, which could be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser via an avatar containing a specially crafted "img" tag.
The second issue is due to an error in the "action_public/moderate.php" script, which could be exploited by malicious moderators to gain moderation access over a forum that they do not normally moderate.
|