CVE-2016-7980: CSRF
Cross-site request forgery (CSRF) vulnerability in ecrire/exec/validerxml.php in SPIP 3.1.2 and earlier allows remote attackers to hijack the authentication of administrators for requests that execute the XML validator on a local file via a crafted validerxml request. NOTE: this issue can be combined with CVE-2016-7998 to execute arbitrary PHP code.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-7980?
CVE-2016-7980 is classified as a medium severity cross-site request forgery (CSRF) vulnerability.
How do I fix CVE-2016-7980?
To fix CVE-2016-7980, upgrade to SPIP version 3.1.3 or later.
Who is affected by CVE-2016-7980?
CVE-2016-7980 affects users of SPIP versions 3.1.2 and earlier.
What is the impact of CVE-2016-7980?
CVE-2016-7980 allows remote attackers to hijack the authentication of administrators and execute local file requests.
Is CVE-2016-7980 a common vulnerability?
As a CSRF vulnerability, CVE-2016-7980 is relatively common in web applications that lack proper request validation.