Jump to content
View in the app

A better way to browse. Learn more.

Invision Community

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

4.1.11.1

  • Released 05/08/2016
  • Current release: No
  • Beta release: No
  • Soft release: No

This is a security release to fix a number of security related issues.

  • A vulnerability was recently discovered in ImageMagick, which, depending on your configuration, IPS Community Suite may use manipulate images. This update verifies that images sent to ImageMagick begin with the expected "magic bytes" corresponding to the image file type.
  • We are engaging in a third-party security audit of IPS Community Suite and this update contains a lot of security hardening. Many of these issues are not critical but we do still want to get the updates to you. 

This release only contains security fixes only. 4.1.12 will be our next general maintenance release.


This is a security release and we recommend all clients upgrade as soon as possible.

In addition to the ImageMagick fix described above, this update contains fixes for the following issues:

  • Session hijacking vulnerabilities with unmunged URLs and with referrer leaking 
  • Several XSS vulnerabilities
  • An open redirect vulnerability
  • Under some circumstances, the reputation activity on a user's profile could reveal the titles of hidden content.
  • Under some circumstances, the "post feed" sidebar widget reveal the titles of hidden content.
  • The "Resend Confirmation Email" and "Change Email" buttons which appear when validating, and the "lost password" tool had no rate limiting, which could allow a malicious user to send lots of emails damaging the server's reputation.
  • Uninstalling an application caused Pages pages to lose their sidebar configurations.

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.