AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2017-8898

CRITICAL · CVSS 9.8 EPSS 1.89%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2017-05-11 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2017-8898
Severity
CRITICAL
CVSS
9.8
EPSS
1.89%

Original Filing — NVD Description

Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has stored XSS in the Announcements, allowing privilege escalation from an Invision Power Board moderator to an admin. An attack uses the announce_content parameter in an index.php?/modcp/announcements/&action=create request. This is related to the "<> Source" option.