High severity8.8NVD Advisory· Published Jun 1, 2021· Updated Jun 17, 2026
CVE-2021-32924
CVE-2021-32924
Description
Invision Community (aka IPS Community Suite) before 4.6.0 allows eval-based PHP code injection by a moderator because the IPS\cms\modules\front\pages\_builder::previewBlock method interacts unsafely with the IPS\_Theme::runProcessFunction method.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:invisioncommunity:ips_community_suite:*:*:*:*:*:*:*:*Range: <4.6.0
- Invision Community/IPS Community Suitedescription
- Range: <4.6.0
Patches
Vulnerability mechanics
References
5- packetstormsecurity.com/files/162868/IPS-Community-Suite-4.5.4.2-PHP-Code-Injection.htmlnvdExploitThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2021/May/80nvdExploitMailing ListThird Party Advisory
- hackerone.com/reports/1092574nvdExploitIssue TrackingThird Party Advisory
- karmainsecurity.com/KIS-2021-04nvdThird Party Advisory
- invisioncommunity.com/features/security/nvdVendor Advisory
News mentions
0No linked articles in our index yet.