Impact
SPIP versions before 4.4.18 contain an unauthenticated blind SQL injection in the SQL escaping layer. Attackers can supply crafted annee parameter values matching a word character followed by an open parenthesis, which bypasses escaping for date‑type columns in MySQL, SQLite, and PostgreSQL. The always‑present sitemap.xml.html template exposes this flaw, enabling injection of unescaped time‑based or boolean payloads. This allows attackers to extract arbitrary database content, including the alea_ephemere secret used to sign SPIP action nonces.
Affected Systems
SPIP content‑management system versions earlier than 4.4.18 are affected.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. Attackers can reach the vulnerable sitemap endpoint over the public network without authentication, making exploitation straightforward. The EPSS score of less than 1% indicates a low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, so it has no known public exploit at present. Based on the description the likely attack vector involves crafting the annee parameter value in the sitemap.xml.html request, but the attack does not require authentication.
OpenCVE Enrichment