Vulnerabilities
Vulnerable Software
Spip:  >> Spip  >> 3.2.4  Security Vulnerabilities
SPIP before 3.1.11 and 3.2 before 3.2.5 allows authenticated visitors to modify any published content and execute other modifications in the database. This is related to ecrire/inc/meta.php and ecrire/inc/securiser_action.php.
CVSS Score
6.5
EPSS Score
0.007
Published
2019-09-17
SPIP before 3.1.11 and 3.2 before 3.2.5 allows prive/formulaires/login.php XSS via error messages.
CVSS Score
6.1
EPSS Score
0.008
Published
2019-09-17
SPIP before 3.1.11 and 3.2 before 3.2.5 mishandles redirect URLs in ecrire/inc/headers.php with a %0D, %0A, or %20 character.
CVSS Score
6.1
EPSS Score
0.004
Published
2019-09-17
SPIP before 3.1.11 and 3.2 before 3.2.5 provides different error messages from the password-reminder page depending on whether an e-mail address exists, which might help attackers to enumerate subscribers.
CVSS Score
5.3
EPSS Score
0.394
Published
2019-09-17


Contact Us

Shodan ® - All rights reserved