Search CVE reports
1 – 10 of 69 results
security update
1 affected package
spip
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| spip | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
security update
1 affected package
spip
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| spip | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
SPIP before 4.4.18 contains a code injection vulnerability in SQLite-backed installations. The navigation menu endpoint improperly handles array-typed user input, which bypasses input sanitization and allows the value to break out...
1 affected package
spip
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| spip | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
action/cookie.php in ecrire in SPIP before 4.4.15 is prone to an open redirect vulnerability.
1 affected package
spip
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| spip | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the public space that is limited to certain nginx configurations, allowing attackers to execute arbitrary code in the context of the web server....
1 affected package
spip
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| spip | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the private space that allows attackers to execute arbitrary code in the context of the web server. Attackers can exploit this vulnerability to achieve...
1 affected package
spip
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| spip | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
SPIP 4.4.10 through 4.4.12 before 4.4.13 allows unintended privilege assignment (of administrator privileges) during the editing of an author data structure because of STATUT mishandling.
1 affected package
spip
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| spip | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
SPIP versions prior to 4.4.10 contain a SQL injection vulnerability that allows authenticated low-privilege users to execute arbitrary SQL queries by manipulating union-based injection techniques. Attackers can exploit this SQL...
1 affected package
spip
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| spip | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
SPIP versions prior to 4.4.10 contain an authentication bypass vulnerability caused by PHP type juggling that allows unauthenticated attackers to access protected information. Attackers can exploit loose type comparisons in...
1 affected package
spip
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| spip | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
SPIP before 4.4.9 allows Insecure Deserialization in the public area through the table_valeur filter and the DATA iterator, which accept serialized data. An attacker who can place malicious serialized content (a pre-condition...
1 affected package
spip
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| spip | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |