Back

MEDIUM

Invision Community 4.5.4 is affected by cross-site scripting (XSS) in the Field Name field

Published Dec 30, 2020

Description

Invision Community 4.5.4 is affected by cross-site scripting (XSS) in the Field Name field. This vulnerability can allow an attacker to inject the XSS payload in Field Name and each time any user will open that, the XSS triggers and the attacker can able to steal the cookie according to the crafted payload.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 30, 2020
Updated Jul 9, 2026
Reserved Dec 2, 2020
NVD
Status Modified
Modified Jul 9, 2026
Red Hat
Severity n/a
Public date n/a