Cross-site scripting (XSS) vulnerability in Invision Power Board 1.3 Final allows remote attackers to execute arbitrary script as other users via the pop parameter in a chat action to index.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Invision_power_board | Invision_power_services | 1.3_final (including) | 1.3_final (including) |