ZeroHour

CVE-2026-33549

CVSS 3.1
8.8 high
EPSS
<1%p15
Published
()
Modified
Description

SPIP 4.4.10 through 4.4.12 before 4.4.13 allows unintended privilege assignment (of administrator privileges) during the editing of an author data structure because of STATUT mishandling.

Vendors
spip
Products
spip
Weakness
CWE-688
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.