PT-2024-23217 · Invision · Invision Community
Egidio Romano
·
Published
2024-04-08
·
Updated
2025-06-05
·
CVE-2024-30163
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Invision Community versions 4.4.0 through 4.7.15
Description
The issue allows for SQL injection via the applications/nexus/modules/front/store/store.php
IPS exusmodulesfrontstore store:: categoryView() method. User input passed through the filter request parameter is not properly sanitized before being used to execute SQL queries. This can be exploited by unauthenticated attackers to carry out Blind SQL Injection attacks.Recommendations
For versions 4.4.0 through 4.7.15, update to version 4.7.16 or later to resolve the issue.
As a temporary workaround, consider restricting access to the
store.php file or the IPS exusmodulesfrontstore store:: categoryView() method until a patch is available.
Avoid using the filter request parameter in the affected API endpoint until the issue is resolved.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Invision Community