Exploit Report

Computer Security And Bug Information

CVE-2023-27372

CVECVE-2023-27372
CVE Title
Published Date2023-02-28T20:15Z
Modified Date2023-03-06T16:26Z
CWE TypeNVD-CWE-noinfo
CVSS 3.xCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
DescriptionSPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1.
References
By clicking these links you will leave this website. We do not endorse and will not be held accountable for any activity on external sites.
Reference URLhttps://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-2-1-SPIP-4-1-8-SPIP-4-0-10-et.html
Reference DescriptionMISC https://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-2-1-SPIP-4-1-8-SPIP-4-0-10-et.html
Reference URLhttps://git.spip.net/spip/spip/commit/5aedf49b89415a4df3eb775eee3801a2b4b88266
Reference DescriptionMISC https://git.spip.net/spip/spip/commit/5aedf49b89415a4df3eb775eee3801a2b4b88266
Reference URLhttps://git.spip.net/spip/spip/commit/96fbeb38711c6706e62457f2b732a652a04a409d
Reference DescriptionMISC https://git.spip.net/spip/spip/commit/96fbeb38711c6706e62457f2b732a652a04a409d
Reference URLhttps://www.debian.org/security/2023/dsa-5367
Reference DescriptionDEBIAN DSA-5367
TagsRelease Notes
Sources NIST MITRE

This site's data is aggregated programmatically and provided "as is" without any representations or warranties, express or implied. Exploit.report is not affiliated with the The MITRE Corporation, U.S. Department of Homeland Security (DHS), Cybersecurity and Infrastructure Security Agency (CISA), or US government in any way. CVE and the CVE logo are registered trademarks of The MITRE Corporation

© 2022 Exploit.Report | Data | Contact | Privacy Policy | Articles