NA

CVE-2024-30162

Published: 07/06/2024 Updated: 07/06/2024

Vulnerability Summary

Invision Community up to and including 4.7.16 allows remote code execution via the applications/core/modules/admin/editor/toolbar.php IPS\core\modules\admin\editor\_toolbar::addPlugin() method. This method handles uploaded ZIP files that are extracted into the applications/core/interface/ckeditor/ckeditor/plugins/ directory without properly verifying their content. This can be exploited by admin users (with the toolbar_manage permission) to write arbitrary PHP files into that directory, leading to execution of arbitrary PHP code in the context of the web server user.

Vulnerability Trend

Exploits

Invision Community versions 4716 and below suffer from a remote code execution vulnerability in toolbarphp ...

Mailing Lists

------------------------------------------------------------------------------ Invision Community <= 4716 (toolbarphp) Remote Code Execution Vulnerability ------------------------------------------------------------------------------ [-] Software Link: invisioncommunitycom [-] Affected Versions: Version 4716 and prior version ...