Impact
SPIP versions before 4.4.18 contain a missing authorization flaw in the ecrire/action/ endpoints, identified as CWE‑862. Unauthenticated attackers can supply a valid CSRF nonce to trigger privileged actions such as editer_auteur, enabling arbitrary password rewrites, even for administrator accounts. The CVSS score of 9.3 underscores the high severity of this privilege escalation.
Affected Systems
All deployments of SPIP older than version 4.4.18 are vulnerable. The issue is located within the SPIP core code and does not rely on external libraries or specific system configurations.
Risk and Exploitability
If an attacker can obtain or guess a CSRF nonce, they can perform the exploit entirely over the network without authentication. The EPSS score is below 1% and the vulnerability is not catalogued in the CISA KEV list, yet the attack requires no additional prerequisites beyond the presence of the vulnerable endpoints. Successful exploitation allows the attacker to reset any user’s password, including administrative accounts, resulting in full site compromise.
OpenCVE Enrichment