PT-2024-23217 · Invision · Invision Community

Egidio Romano

·

Published

2024-04-08

·

Updated

2025-06-05

·

CVE-2024-30163

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Invision Community versions 4.4.0 through 4.7.15
Description The issue allows for SQL injection via the applications/nexus/modules/front/store/store.php IPS exusmodulesfrontstore store:: categoryView() method. User input passed through the filter request parameter is not properly sanitized before being used to execute SQL queries. This can be exploited by unauthenticated attackers to carry out Blind SQL Injection attacks.
Recommendations For versions 4.4.0 through 4.7.15, update to version 4.7.16 or later to resolve the issue. As a temporary workaround, consider restricting access to the store.php file or the IPS exusmodulesfrontstore store:: categoryView() method until a patch is available. Avoid using the filter request parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-30163

Affected Products

Invision Community