Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Invision Community 4.5.4 is affected by cross-site scripting (XSS) in the Field Name field. This vulnerability can allow an attacker to inject the XSS payload in Field Name and each time any user will open that, the XSS triggers and the attacker can able to steal the cookie according to the crafted payload.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Invision Community 跨站脚本漏洞
Vulnerability Description
Invision Community是美国Invision公司的一个用于设计、开发移动应用UI的软件。 Invision Community 4.5.4版本存在跨站脚本漏洞,该漏洞允许攻击者将XSS有效载荷注入字段Name中,每当任何用户打开它时,XSS就会触发,攻击者可利用该漏洞可以根据精心制作的有效载荷窃取cookie。
CVSS Information
N/A
Vulnerability Type
N/A