A Server-Side Request Forgery (SSRF) vulnerability in IPS Community Suite before 4.6.2 allows remote authenticated users to request arbitrary URLs or trigger deserialization via phar protocol when generating class names dynamically. In some cases an exploitation is possible by an unauthenticated user.
References
Link | Resource |
---|---|
https://invisioncommunity.com/release-notes/462-r99/ | Release Notes Vendor Advisory |
Configurations
History
27 Jun 2022, 16:40
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 6.4
v3 : 9.1 |
CPE | cpe:2.3:a:invisioncommunity:ips_community_suite:*:*:*:*:*:*:*:* | |
References | (MISC) https://invisioncommunity.com/release-notes/462-r99/ - Release Notes, Vendor Advisory | |
CWE | CWE-918 |
13 Jun 2022, 18:22
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-06-13 18:15
Updated : 2024-02-04 22:29
NVD link : CVE-2021-40604
Mitre link : CVE-2021-40604
CVE.ORG link : CVE-2021-40604
JSON object : View
Products Affected
invisioncommunity
- ips_community_suite
CWE
CWE-918
Server-Side Request Forgery (SSRF)