标题:Invision Community 安全漏洞 (CVE-2024-30163) Description:Invision Community是美国Invision公司的一个用于设计、开发移动应用UI的软件。 Invision Community 4.7.16之前版本存在安全漏洞,该漏洞源于应用程序未能正确地对请求参数进行清理,未经身份验证的攻击者可以利用这个漏洞执行盲SQL注入攻击。
Description
IPS Community Suite is vulnerable to unauthenticated SQL injection via the filter[] parameter in the /index.php?/store/ endpoint, allowing attackers to extract sensitive information from the database.