prive/formulaires/configurer_preferences.php in SPIP before 3.2.8 does not properly validate the couleur, display, display_navigation, display_outils, imessage, and spip_ecran parameters.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2020-11-23T21:48:53

Updated: 2024-08-04T16:48:01.703Z

Reserved: 2020-11-23T00:00:00

Link: CVE-2020-28984

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-11-23T22:15:12.570

Modified: 2021-02-04T15:05:16.840

Link: CVE-2020-28984

cve-icon Redhat

No data.