SPIP 4.0.0 is affected by a Cross Site Request Forgery (CSRF) vulnerability in ecrire/public/aiguiller.php, ecrire/public/balises.php, ecrire/balise/formulaire_.php. To exploit the vulnerability, a visitor must visit a malicious website which redirects to the SPIP website. It is also possible to combine XSS vulnerabilities in SPIP 4.0.0 to exploit it. The vulnerability allows an authenticated attacker to execute malicious code without the knowledge of the user on the website (CSRF).
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2022-01-26T11:47:55
Updated: 2024-08-04T04:10:17.382Z
Reserved: 2021-11-22T00:00:00
Link: CVE-2021-44122
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-01-26T12:15:07.887
Modified: 2024-11-21T06:30:24.030
Link: CVE-2021-44122
Redhat
No data.