CVE-2021-32924: Code Injection
Published Jun 1, 2021
·Updated
Invision Community (aka IPS Community Suite) before 4.6.0 allows eval-based PHP code injection by a moderator because the IPS\cms\modules\front\pages\builder::previewBlock method interacts unsafely with the IPS\Theme::runProcessFunction method.
Affected Software
1 affected component
Invisioncommunity Ips Community Suite<4.6.0
Event History
Jun 1, 2021
CVE Published
via MITRE·05:47 PM
Data Sourced
via MITRE·05:47 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Invision Community (aka IPS Community Suite) vulnerability?
The vulnerability ID for this Invision Community (aka IPS Community Suite) vulnerability is CVE-2021-32924.
2
What is the severity of CVE-2021-32924 vulnerability?
The severity of CVE-2021-32924 vulnerability is high (8.8).
3
How does CVE-2021-32924 allow PHP code injection?
CVE-2021-32924 allows eval-based PHP code injection by a moderator through the IPS\cms\modules\front\pages\_builder::previewBlock method.
4
Which version of Invision Community (aka IPS Community Suite) is affected by CVE-2021-32924?
Invision Community (aka IPS Community Suite) before version 4.6.0 is affected by CVE-2021-32924.
5
How can I fix CVE-2021-32924 vulnerability?
To fix CVE-2021-32924 vulnerability, update Invision Community Suite to version 4.6.0 or above.