VYPR

Ips

by Invision Power Services

CVEs (1)

  • CVE-2024-30162HigJun 7, 2024
    risk 0.47cvss 7.2epss 0.01

    Invision Community through 4.7.16 allows remote code execution via the applications/core/modules/admin/editor/toolbar.php IPS\core\modules\admin\editor\_toolbar::addPlugin() method. This method handles uploaded ZIP files that are extracted into the…