CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Invisioncommunity 1Ips Community Suite Nov 21, 2024 Jun 13, 2022 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A Server-Side Request Forgery (SSRF) vulnerability in IPS Community Suite before 4.6.2 allows remote authenticated users to request arbitrary URLs or trigger deserialization via phar protocol when generating class names...Show more |
1Invisioncommunity 1Ips Community Suite Nov 21, 2024 Jun 1, 2021 N/A· v4 8.8 HIGH· v3 6.0 MEDIUM· v2 Invision Community (aka IPS Community Suite) before 4.6.0 allows eval-based PHP code injection by a moderator because the IPS\cms\modules\front\pages\_builder::previewBlock method interacts unsafely with the IPS\_Theme::...Show more |
1Invisioncommunity 1Ips Community Suite Nov 21, 2024 Jan 8, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Invision Community IPS Community Suite before 4.5.4.2 allows SQL Injection via the Downloads REST API (the sortDir parameter in a sortBy=popular action to the GETindex() method in applications/downloads/api/files.php). |
1Invisioncommunity 1Ips Community Suite Nov 21, 2024 Jan 5, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Invision Community IPS Community Suite before 4.5.4.2 allows XSS during the quoting of a post or comment. |