CVE-2016-9152: XSS
Published Dec 5, 2016
·Updated
Cross-site scripting (XSS) vulnerability in ecrire/exec/plonger.php in SPIP 3.1.3 allows remote attackers to inject arbitrary web script or HTML via the rac parameter.
Affected Software
1 affected component
Spip SPIP=3.1.3
Remediation
Event History
Dec 5, 2016
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-9152?
CVE-2016-9152 has a medium severity rating due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2016-9152?
To fix CVE-2016-9152, update your SPIP installation to a version newer than 3.1.3 that addresses this vulnerability.
3
What type of vulnerability is CVE-2016-9152?
CVE-2016-9152 is classified as a cross-site scripting (XSS) vulnerability.
4
Who is affected by CVE-2016-9152?
CVE-2016-9152 affects users of SPIP version 3.1.3.
5
What can attackers do with CVE-2016-9152?
Attackers can exploit CVE-2016-9152 to inject arbitrary web scripts or HTML into the affected application.