Description
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3347-2 | spip regression update |
Debian DSA |
DSA-5367-1 | spip security update |
Ubuntu USN |
USN-7318-1 | SPIP vulnerabilities |
References
History
Tue, 11 Mar 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-11T14:27:45.289Z
Reserved: 2023-02-28T00:00:00.000Z
Link: CVE-2023-27372
Updated: 2024-08-02T12:09:43.355Z
Status : Modified
Published: 2023-02-28T20:15:10.243
Modified: 2025-03-11T15:15:38.177
Link: CVE-2023-27372
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
Ubuntu USN