LiveActive security incident?Get immediate response
CVE Record

CVE-2021-39249: Invision Community (aka IPS Community Suite or IP-Board) before 4.6.5.1 allows reflected XSS because the fi...

Invision Community (aka IPS Community Suite or IP-Board) before 4.6.5.1 allows reflected XSS because the filenames of uploaded files become predictable through a brute-force attack against the PHP mt_rand function.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

Older Invision Community/IP-Board sites could expose users to script injection because uploaded filenames may be guessed. A successful attack could affect user sessions or site trust, depending on privileges and configuration. The bundle does not show confirmed exploitation, but public disclosure and vendor release notes make upgrade verification important.

Executive priority

Prioritize remediation for public forums or customer communities running affected versions. The business risk is user compromise and reputational damage, with possible higher impact if the advisory chain applies. No active exploitation is evidenced in the provided bundle.

Technical view

CVE-2021-39249 affects Invision Community before 4.6.5.1. The CVE describes reflected XSS caused by predictable uploaded-file filenames after brute forcing PHP mt_rand output. The SSD advisory title indicates a broader stored-XSS-to-RCE chain, but this bundle does not provide enough detail to independently characterize the full chain.

Likely exposure

Exposure is most likely on internet-facing Invision Community, IPS Community Suite, or IP-Board installations older than 4.6.5.1, especially where file upload functionality is available to users.

Exploitation context

CISA KEV status is false in the bundle, and no cited source here confirms active exploitation. The issue is publicly disclosed, and the linked advisory discusses a more serious chain, so defenders should treat public-facing legacy deployments as higher priority.

Researcher notes

Evidence is limited to the CVE description, SSD advisory link, and Invision 4.6.5.1 release notes. Treat the reflected XSS mechanism as sourced; treat any RCE implications cautiously unless confirmed by the full advisory or vendor documentation.

Mitigation direction

  • Upgrade Invision Community/IP-Board to 4.6.5.1 or later.
  • Review Invision release notes and vendor guidance for related security fixes.
  • Inventory public community sites and confirm exact installed versions.
  • Limit untrusted upload capability where business operations allow.
  • Increase monitoring for suspicious upload and script-injection activity.

Validation and detection

  • Check whether any deployment runs Invision Community before 4.6.5.1.
  • Confirm exposed sites allow user-controlled file uploads.
  • Review web logs for unusual upload filename probing patterns.
  • Verify the vendor security update is installed in production.
  • Confirm no unreviewed customizations bypass upload handling controls.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2021-39249 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.