Impact
The vulnerability is a mass assignment flaw in SPIP's editer_objet action before 4.4.18. It permits unauthenticated attackers to write arbitrary rows to any SQL table that lacks a champs_editables allowlist by providing an arg parameter that resolves to internal database tables. By inserting a malicious row into the spip_jobs queue with a controlled PHP function and arguments, the cron daemon dynamically executes this payload when the queue is processed, yielding remote code execution. This failure of input validation and sanitization corresponds to CWE‑915.
Affected Systems
SPIP installations of any version earlier than 4.4.18 are affected. The vendor, SPIP, publishes a security update in version 4.4.18 that addresses this issue. The affected component is the editer_objet.php script and the spip_jobs queue mechanism.
Risk and Exploitability
The CVSS score of 9.3 marks this flaw as critical. The attack does not require authentication; an unauthenticated user can send a crafted request to editer_objet.php with an arg value that points to internal database tables. The injected row in the spip_jobs queue is executed only when the cron daemon drains the queue, allowing the attacker to trigger code execution at a later time. The EPSS score is <1%, indicating a low but non‑zero probability of exploitation in the wild, and the vulnerability is not listed in CISA KEV. The combination of critical severity, unauthenticated access, and delayed execution makes this a high‑priority issue that warrants immediate remediation.
OpenCVE Enrichment