Impact
The SPIP tickets plugin contains an unauthenticated remote code execution flaw in versions prior to 4.3.3. The flaw arises when the forum preview handling for public ticket pages appends untrusted request parameters into HTML, which is later rendered by a template using unfiltered environment rendering (#ENV). This bypasses SPIP’s output filtering and allows an attacker to inject crafted content that is evaluated by the template processing chain, resulting in execution of code in the web server context.
Affected Systems
Console and web servers running the SPIP tickets plugin with a version prior to 4.3.3 are affected. The vulnerability is present in all releases of the tickets plugin below the 4.3.3 update that users should migrate to.
Risk and Exploitability
The flaw carries a CVSS score of 9.3, indicating critical severity. Its EPSS score is currently below 1 %, suggesting low exploitation probability at present, and it is not listed in CISA’s Known Exploited Vulnerabilities catalog. However, the vulnerability is exploitable by any unauthenticated user through the public ticket page preview interface, requiring no special credentials. The combination of a high severity rating and the lack of authentication requirements means that an attacker could achieve remote code execution with minimal effort once the flaw existed in the environment.
OpenCVE Enrichment