prive/formulaires/configurer_preferences.php in SPIP before 3.2.8 does not properly validate the couleur, display, display_navigation, display_outils, imessage, and spip_ecran parameters.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-2505-1 spip security update
Debian DSA Debian DSA DSA-4798-1 spip security update
EUVD EUVD EUVD-2020-21367 prive/formulaires/configurer_preferences.php in SPIP before 3.2.8 does not properly validate the couleur, display, display_navigation, display_outils, imessage, and spip_ecran parameters.
Ubuntu USN Ubuntu USN USN-5482-1 SPIP vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T16:48:01.703Z

Reserved: 2020-11-23T00:00:00

Link: CVE-2020-28984

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-11-23T22:15:12.570

Modified: 2024-11-21T05:23:26.607

Link: CVE-2020-28984

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.