cve/2021/CVE-2021-32924.md
2024-06-18 02:51:15 +02:00

813 B

CVE-2021-32924

Description

Invision Community (aka IPS Community Suite) before 4.6.0 allows eval-based PHP code injection by a moderator because the IPS\cms\modules\front\pages_builder::previewBlock method interacts unsafely with the IPS_Theme::runProcessFunction method.

POC

Reference

Github

No PoCs found on GitHub currently.