Invision Community 4.5.4 is affected by cross-site scripting (XSS) in the Field Name field. This vulnerability can allow an attacker to inject the XSS payload in Field Name and each time any user will open that, the XSS triggers and the attacker can able to steal the cookie according to the crafted payload.
📦
community
Vendor: invisioncommunity
Actively Exploited
0
CISA KEV List
PoC / Exploits
1
Code Available
Total RCEs
0
Remote Access
Total CVEs
3
Total Indexed
Avg. EPSS
0.83%
Exploit Prob.
Security Vulnerability Index
Page 1 / 1
4.8
CVSS
CVE-2020-29477
Exploit Found
Severity: MEDIUM
5.4
CVSS
XSS in Telligent Community 5.6.583.20496 via a flash file and related to the allowScriptAccess parameter.
Severity: MEDIUM
6.1
CVSS
Telligent Community 6.x, 7.x, 8.x, 9.x before 9.2.10.11796, 10.1.x before 10.1.10.11792, and 10.2.x before 10.2.3.4725 has XSS via the Feed RSS widget.
Severity: MEDIUM