SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2023-02-28T00:00:00

Updated: 2024-08-02T12:09:43.355Z

Reserved: 2023-02-28T00:00:00

Link: CVE-2023-27372

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-02-28T20:15:10.243

Modified: 2023-06-21T18:15:12.797

Link: CVE-2023-27372

cve-icon Redhat

No data.