SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2007-4914

Unspecified vulnerability in the subscriptions manager in Invision Power Board (IPB or IP.Board) 2.3.1 before 20070912 allows remote authenticated users to change the member ID and reduce the privilege level of arbitrary users via a crafted payment…

MEDIUM 6.0EPSS 1.38%

Does this matter?

Lower severity and a low EPSS score (1.38%). Track it; it rarely justifies an emergency change on its own.

Description

Unspecified vulnerability in the subscriptions manager in Invision Power Board (IPB or IP.Board) 2.3.1 before 20070912 allows remote authenticated users to change the member ID and reduce the privilege level of arbitrary users via a crafted payment form, related to (1) class_gw_2checkout.php, (2) class_gw_authorizenet.php, (3) class_gw_nochex.php, (4) class_gw_paypal.php, and (5) class_gw_safshop.php in sources/classes/paymentgateways/.

CVSS 2.0
6.0 MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
EPSS
1.38% probability · 71th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
invision power services/invision power board
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.