Generated remediation guidance and an executive summary. No account required.
Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has a composite of Stored XSS and Information Disclosure issues in the attachments feature found in User CP. This can be triggered by any Invision Power Board user and can be used to gain access to moderator/admin accounts. The primary cause is the ability to upload an SVG document with a crafted attribute such an onload; however, full path disclosure is required for exploitation.
Use CWE-79, Invisioncommunity vendor hub and Invision Power Board product page to widen CVE-2017-8899 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2013-3725, CVE-2012-2226 and CVE-2017-8898 for nearby disclosures in the same product family.