CVE-2024-30162

Invision Community through 4.7.16 allows remote code execution via the applications/core/modules/admin/editor/toolbar.php IPS\core\modules\admin\editor\_toolbar::addPlugin() method. This method handles uploaded ZIP files that are extracted into the applications/core/interface/ckeditor/ckeditor/plugins/ directory without properly verifying their content. This can be exploited by admin users (with the toolbar_manage permission) to write arbitrary PHP files into that directory, leading to execution of arbitrary PHP code in the context of the web server user.
Configurations

No configuration.

History

No history.

Information

Published : 2024-06-07 17:15

Updated : 2024-07-03 01:53


NVD link : CVE-2024-30162

Mitre link : CVE-2024-30162

CVE.ORG link : CVE-2024-30162


JSON object : View

Products Affected

No product.

CWE
CWE-345

Insufficient Verification of Data Authenticity