👀 You are watching:
Jump to content
👉 Click here to explore Remote Jobs, Work From Home & Global News – USA 🇺🇸 | UK 🇬🇧 | Canada 🇨🇦 | Pakistan 🇵🇰 ×
🚫 Guest Access Notice ×
  • Download trusted applications for Invision Community only on FundayForum.com — your entertainment & community resource hub.

2 Screenshots

About This File

 

This is a security release and we recommend all clients upgrade as soon as possible.

Dont be leech click at like and share forum link with others. 

 

Key Changes

This is a security release to fix a number of security related issues.

  • A vulnerability was recently discovered in ImageMagick, which, depending on your configuration, IPS Community Suite may use manipulate images. This update verifies that images sent to ImageMagick begin with the expected "magic bytes" corresponding to the image file type.
  • We are engaging in a third-party security audit of IPS Community Suite and this update contains a lot of security hardening. Many of these issues are not critical but we do still want to get the updates to you. 

 

This release only contains security fixes only. 4.1.12 will be our next general maintenance release.

 

Additional Information

In addition to the ImageMagick fix described above, this update contains fixes for the following issues:

  • Session hijacking vulnerabilities with unmunged URLs and with referrer leaking 
  • Several XSS vulnerabilities
  • An open redirect vulnerability
  • Under some circumstances, the reputation activity on a user's profile could reveal the titles of hidden content.
  • Under some circumstances, the "post feed" sidebar widget reveal the titles of hidden content.
  • The "Resend Confirmation Email" and "Change Email" buttons which appear when validating, and the "lost password" tool had no rate limiting, which could allow a malicious user to send lots of emails damaging the server's reputation.
  • Uninstalling an application caused Pages pages to lose their sidebar configurations.

User Feedback

Recommended Comments

There are no comments to display.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Add a comment...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...