S4E just found a low-severity finding from prtg monitoring system detection scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated May 31, 2025

CVE-2024-30163 Scanner

CVE-2024-30163 Scanner - SQL Injection vulnerability in IPS Community Suite

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.1k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.
Description

Invision Community before 4.7.16 allow SQL injection via the applications/nexus/modules/front/store/store.php IPS\nexus\modules\front\store\_store::_categoryView() method, where user input passed through the filter request parameter is not properly sanitized before being used to execute SQL queries. This can be exploited by unauthenticated attackers to carry out Blind SQL Injection attacks.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Sep 18, 2026View on NVD →
Detail

IPS Community Suite is a comprehensive software solution used to power online communities, forums, and e-commerce platforms. It's widely utilized by organizations aiming to build resilient, interactive social networks. Many businesses choose this suite for its expansive features and support. The suite allows users to create customizable and manageable community experiences. Due to its popularity, it is a common target for various cyber threats. Keeping the suite secure is crucial for protecting user interactions and data.

SQL Injection is a critical vulnerability that allows attackers to interfere with the queries that an application makes to its database. It is one of the oldest and most dangerous web application security risks. This vulnerability occurs when untrusted data is sent to an interpreter as part of a command or query, tricking the interpreter into executing unintended commands. SQL Injection can lead to unauthorized viewing of the company's data, modification or deletion of database entries, and in some cases complete administrator access to the application.

The vulnerability in IPS Community Suite is found in the /index.php?/store/ endpoint, specifically the filter[] parameter. This endpoint is vulnerable to SQL Injection, enabling attackers to insert or "inject" SQL code into the backend database. Attackers can use this flaw to manipulate the SQL statements executed by the database server. This could be exploited to extract sensitive information or perform other harmful actions on the database.

Exploiting SQL Injection could potentially compromise the entire database of the affected application. It might allow attackers access to confidential data, such as user passwords and personal information. In extreme cases, attackers could leverage this vulnerability to gain full control over the server, leading to data loss or tampering with sensitive data. Additionally, attackers could use the compromised system to launch further attacks on networked systems.

REFERENCES

Solution Advice
  • Update to the latest version of IPS Community Suite to patch the vulnerability.
  • Audit and secure any exposed endpoints and parameters that might be vulnerable.
  • Use parameterized queries or prepared statements to avoid SQL Injection.
  • Employ web application firewalls to detect and block malicious requests.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.