Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Invision Community (aka IPS Community Suite) before 4.6.0 allows eval-based PHP code injection by a moderator because the IPS\cms\modules\front\pages\_builder::previewBlock method interacts unsafely with the IPS\_Theme::runProcessFunction method.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Invision Community 代码注入漏洞
Vulnerability Description
Invision Community是美国Invision公司的一个用于设计、开发移动应用UI的软件。 IPS Community Suite 4.5.4.2版本及之前版本存在代码注入漏洞,该漏洞源于IPScmsmodulesfrontpages\_builder::previewBlock()方法在调用PHP的eval()函数。
CVSS Information
N/A
Vulnerability Type
N/A