Vulnerabilities
Vulnerable Software
Spip:  >> Spip  >> 3.1.8  Security Vulnerabilities
SPIP before 3.1.11 and 3.2 before 3.2.5 allows authenticated visitors to modify any published content and execute other modifications in the database. This is related to ecrire/inc/meta.php and ecrire/inc/securiser_action.php.
CVSS Score
6.5
EPSS Score
0.007
Published
2019-09-17
SPIP before 3.1.11 and 3.2 before 3.2.5 allows prive/formulaires/login.php XSS via error messages.
CVSS Score
6.1
EPSS Score
0.008
Published
2019-09-17
SPIP before 3.1.11 and 3.2 before 3.2.5 mishandles redirect URLs in ecrire/inc/headers.php with a %0D, %0A, or %20 character.
CVSS Score
6.1
EPSS Score
0.004
Published
2019-09-17
SPIP before 3.1.11 and 3.2 before 3.2.5 provides different error messages from the password-reminder page depending on whether an e-mail address exists, which might help attackers to enumerate subscribers.
CVSS Score
5.3
EPSS Score
0.394
Published
2019-09-17
SPIP 3.1 before 3.1.10 and 3.2 before 3.2.4 allows authenticated visitors to execute arbitrary code on the host server because var_memotri is mishandled.
CVSS Score
8.8
EPSS Score
0.027
Published
2019-04-10


Contact Us

Shodan ® - All rights reserved