ZeroHour

CVE-2023-27372

CVSS 3.1
9.8 critical
EPSS
100%p100
Published
()
Modified
Description

SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1.

Vendors
spipdebian
Products
spip, debian linux
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.