CVE-2007-4914
Unspecified vulnerability in the subscriptions manager in Invision Power Board (IPB or IP.Board) 2.3.1 before 20070912 allows remote authenticated users to change the member ID and reduce the privilege level of arbitrary users via a crafted payment…
Does this matter?
Lower severity and a low EPSS score (1.38%). Track it; it rarely justifies an emergency change on its own.
Description
Unspecified vulnerability in the subscriptions manager in Invision Power Board (IPB or IP.Board) 2.3.1 before 20070912 allows remote authenticated users to change the member ID and reduce the privilege level of arbitrary users via a crafted payment form, related to (1) class_gw_2checkout.php, (2) class_gw_authorizenet.php, (3) class_gw_nochex.php, (4) class_gw_paypal.php, and (5) class_gw_safshop.php in sources/classes/paymentgateways/.
- CVSS 2.0
- 6.0 MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
- EPSS
- 1.38% probability · 71th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- invision power services/invision power board
- Source
- cve@mitre.org
References
- http://forums.invisionpower.com/index.php?act=attach&type=post&id=11870Patch
- http://forums.invisionpower.com/index.php?showtopic=237075Patch
- http://osvdb.org/41319
- http://osvdb.org/41320
- http://osvdb.org/41321
- http://osvdb.org/41322
- http://osvdb.org/41323
- http://secunia.com/advisories/26788Vendor Advisory
- http://www.securityfocus.com/bid/25656
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36590
- http://forums.invisionpower.com/index.php?act=attach&type=post&id=11870Patch
- http://forums.invisionpower.com/index.php?showtopic=237075Patch
- http://osvdb.org/41319
- http://osvdb.org/41320
- http://osvdb.org/41321
- http://osvdb.org/41322
- http://osvdb.org/41323
- http://secunia.com/advisories/26788Vendor Advisory
- http://www.securityfocus.com/bid/25656
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36590
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.