CVE | CVE-2023-27372 |
CVE Title | |
Published Date | 2023-02-28T20:15Z |
Modified Date | 2023-03-06T16:26Z |
CWE Type | NVD-CWE-noinfo |
CVSS 3.x | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Description | SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1. |
References | |
By clicking these links you will leave this website. We do not endorse and will not be held accountable for any activity on external sites. | |
Reference URL | https://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-2-1-SPIP-4-1-8-SPIP-4-0-10-et.html |
Reference Description | MISC https://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-2-1-SPIP-4-1-8-SPIP-4-0-10-et.html |
Reference URL | https://git.spip.net/spip/spip/commit/5aedf49b89415a4df3eb775eee3801a2b4b88266 |
Reference Description | MISC https://git.spip.net/spip/spip/commit/5aedf49b89415a4df3eb775eee3801a2b4b88266 |
Reference URL | https://git.spip.net/spip/spip/commit/96fbeb38711c6706e62457f2b732a652a04a409d |
Reference Description | MISC https://git.spip.net/spip/spip/commit/96fbeb38711c6706e62457f2b732a652a04a409d |
Reference URL | https://www.debian.org/security/2023/dsa-5367 |
Reference Description | DEBIAN DSA-5367 |
Tags | Release Notes |
Sources | NIST MITRE |