CVE-2024-30162

HIGH

Invision Community <= 4.7.16 - Authenticated Remote Code Execution via ZIP Upload in Editor Toolbar Plugin

Title source: llm
STIX 2.1

Description

Invision Community through 4.7.16 allows remote code execution via the applications/core/modules/admin/editor/toolbar.php IPS\core\modules\admin\editor\_toolbar::addPlugin() method. This method handles uploaded ZIP files that are extracted into the applications/core/interface/ckeditor/ckeditor/plugins/ directory without properly verifying their content. This can be exploited by admin users (with the toolbar_manage permission) to write arbitrary PHP files into that directory, leading to execution of arbitrary PHP code in the context of the web server user.

References (2)

Core 2

Scores

CVSS v3 7.2
EPSS 0.0070
EPSS Percentile 48.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-345
Status published
Published Jun 07, 2024
Tracked Since Feb 18, 2026