We found results for “”
CVE-2023-27372
Good to know:
Date: February 27, 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1.
Language: PHP
Severity Score
Related Resources (11)
Severity Score
Weakness Type (CWE)
Deserialization of Untrusted Data
CWE-502Insufficient Information
NVD-CWE-noinfoTop Fix
Upgrade Version
Upgrade to version spip/ecrire - 3.0.29;spip/ecrire - 3.1.10;spip/ecrire - 3.2.4;bdegoy/oauthsd - no_fix
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | HIGH |
| Integrity (I): | HIGH |
| Availability (A): | HIGH |
Vulnerabilities
Projects
Contact Us


