CVE-2024-30163
Last modified
CVE-2024-30163 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Invision Community before 4.7.16 allow SQL injection via the applications/nexus/modules/front/store/store.php IPS\nexus\modules\front\store\_store::_categoryView() method, where user input passed through the filter request parameter is not properly sanitized before being used to execute SQL queries. This can be exploited by unauthenticated attackers to carry out Blind SQL Injection attacks.. EPSS estimates a 8.68% chance of exploitation in the next 30 days.
Description
Invision Community before 4.7.16 allow SQL injection via the applications/nexus/modules/front/store/store.php IPS\nexus\modules\front\store\_store::_categoryView() method, where user input passed through the filter request parameter is not properly sanitized before being used to execute SQL queries. This can be exploited by unauthenticated attackers to carry out Blind SQL Injection attacks.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Invisioncommunity | Invisioncommunity | >= 4.4.0, < 4.7.16 |
References
- http://seclists.org/fulldisclosure/2024/Apr/20Exploit, Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2024/Apr/20Exploit, Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-30163?
How severe is CVE-2024-30163?
How do I fix CVE-2024-30163?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-30158A vulnerability in the web conferencing component of Mitel M…7.2
- CVE-2024-30159A vulnerability in the web conferencing component of Mitel M…4.8
- CVE-2024-3016NEC Platforms DT900 and DT900S Series 5.0.0.0 – v5.3.4.4, v5…9.1
- CVE-2024-30160A vulnerability in the Suite Applications Services component…4.8
- CVE-2024-30161In Qt 6.5.4, 6.5.5, and 6.6.2, QNetworkReply header data mig…6.5
- CVE-2024-30162Invision Community through 4.7.16 allows remote code executi…7.2
- CVE-2024-30164Amazon AWS Client VPN has a buffer overflow that could poten…6.7
- CVE-2024-30165Amazon AWS Client VPN before 3.9.1 on macOS has a buffer ove…7.1
- CVE-2024-30166In Mbed TLS 3.3.0 through 3.5.2 before 3.6.0, a malicious cl…9.1
- CVE-2024-30167/cgi-bin/time.cgi in Atlona AT-OME-MS42 Matrix Switcher 1.1.…6.3
- CVE-2024-3017In a Silicon Labs multi-protocol gateway, a corrupt point…6.5
- CVE-2024-30170PrivX before 34.0 allows data exfiltration and denial of ser…9.1
Are you affected by CVE-2024-30163?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
