NA

CVE-2023-24258

Published: 27/02/2023 Updated: 24/03/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

SPIP v4.1.5 and previous versions exists to contain a SQL injection vulnerability via the _oups parameter. This vulnerability allows malicious users to execute arbitrary code via a crafted POST request.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

spip spip