logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2024-30163

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2024-30163

Description:
Invision Community before 4.7.16 allow SQL injection via the applications/nexus/modules/front/store/store.php IPS\nexus\modules\front\store\_store::_categoryView() method, where user input passed through the filter request parameter is not properly sanitized before being used to execute SQL queries. This can be exploited by unauthenticated attackers to carry out Blind SQL Injection attacks.
Last updated date:
08/08/2024
Type:
exploit
Confidence:
HIGH
Date of publishing:
08/08/2024
Reference url to background

http://seclists.org/fulldisclosure/2024/Apr/20

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy