Invision Power Services has released patches for IP.Board 3.3.x and 3.4.x in order to address a couple of cross-site scripting (XSS) vulnerabilities. Artur Czyż and indistic have been credited for finding and reporting the security holes.
IP.Board takes precaution against cross site scripting issues by ensuring sensitive forms and buttons have a unique key in them and also by ensuring that sensitive cookie data is not readable by javascript. However, we feel t…