Impact
The Crayons plugin for SPIP before version 3.5.0 contains a missing authorization flaw; unauthenticated attackers can omit the secu_ anti‑forgery parameter in crayons_store.php, causing the dispatcher to resolve a handler that always evaluates true. This allows arbitrary modifications of editable object fields, the upload of a malicious .html skeleton, disclosure of sensitive configuration files, and the forging of a signed AJAX context so that the uploaded skeleton is executed as PHP code running under the web server account. The weakness is a classic authorization bypass (CWE-862) and results in remote code execution.
Affected Systems
The vulnerability affects installations of the SPIP Crayons Plugin earlier than version 3.5.0. Any site using an older, unpatched plugin version is potentially exposed.
Risk and Exploitability
The CVSS score of 9.3 indicates a critical severity. Although no EPSS value is available, the lack of a KEV listing and the high score imply the flaw is likely to be exploited if left unpatched. Attackers do not require authentication and can reach the vulnerable code through the web interface, so the attack vector is remote, HTTP‑based. The combination of a missing anti‑forgery check, the ability to modify arbitrary fields, and the ability to execute uploaded code makes exploitation straightforward once the plugin is accessed.
OpenCVE Enrichment