6.1
CVSSv3

CVE-2023-52322

Published: 04/01/2024 Updated: 15/03/2024
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

ecrire/public/assembler.php in SPIP prior to 4.1.13 and 4.2.x prior to 4.2.7 allows XSS because input from _request() is not restricted to safe characters such as alphanumerics.

Vulnerable Product Search on Vulmon Subscribe to Product

spip spip