CVE-2016-6174 | Invision Power Board up to 4.1.12 on PHP5 content.php content_class privileges management (ID 137804 / EDB-40084)
A vulnerability classified as critical has been found in Invision Power Board up to 4.1.12 on PHP5. This affects an unknown part of the file applications/core/modules/front/system/content.php. The manipulation of the argument content_class leads to improper privilege management.
This vulnerability is uniquely identified as CVE-2016-6174. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.