Impact
SPIP before version 4.4.18 on SQLite installations has a code injection flaw. The navigation endpoint accepts array‑typed user input that bypasses sanitization, letting the payload break out of an internal quoted string when PHP evaluates it. An authenticated user with at least editor rights can send a single crafted GET request to /ecrire/?exec=navigation and run arbitrary operating‑system commands under the web‑server process, compromising confidentiality, integrity, and availability of the system.
Affected Systems
Affected products are SPIP installations using SQLite as the database engine and running any version earlier than 4.4.18. MySQL‑backed installations are not impacted.
Risk and Exploitability
The CVSS score of 7.7 indicates a high‑severity vulnerability with full code execution. No EPSS score is available, so the exploitation probability is unknown. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is through authenticated HTTP requests from users who have editor privileges. The attack requires no special configuration beyond the documented input handling flaw.
OpenCVE Enrichment
Debian DSA