About This File
Invision Community Suite 4.4.10
WebFlake Release Date: 2/20/2020
WebFlake Note: Please create a support topic in IPS Support if you need assistance.
What's New in Version 4.4.9.1 See changelog
Released
Additional Information
Security
- Block binary/octal/hex/decimal based hostnames from being submitted in forms that could trigger an SSRF.
- Gfycat OEmbed endpoint could create XSS. Also informed Gfycat of issue. - Thanks to René Kroka - https://renekroka.cz for reporting this issue.
- Addition attachment permission checks when downloading attachments.