CVE-2016-9998: XSS
Published Dec 17, 2016
·Updated
SPIP 3.1.x suffer from a Reflected Cross Site Scripting Vulnerability in /ecrire/exec/infoplugin.php involving the $plugin parameter, as demonstrated by a /ecrire/?exec=infoplugin URL.
Affected Software
9 affected components
Spip SPIP=3.1.0
Spip SPIP=3.1.0-alpha
Spip SPIP=3.1.0-beta
Spip SPIP=3.1.0-rc
Spip SPIP=3.1.0-rc2
Spip SPIP=3.1.0-rc3
Spip SPIP=3.1.1
Spip SPIP=3.1.2
Spip SPIP=3.1.3
Remediation
Event History
Dec 17, 2016
CVE Published
via MITRE·03:34 AM
Data Sourced
via MITRE·03:34 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-9998?
CVE-2016-9998 has a medium severity rating due to its potential for reflected cross-site scripting attacks.
2
How do I fix CVE-2016-9998?
To fix CVE-2016-9998, upgrade SPIP to version 3.1.4 or later where the vulnerability is patched.
3
What applications are affected by CVE-2016-9998?
CVE-2016-9998 affects SPIP versions 3.1.0 through 3.1.3, including alpha, beta, and release candidate versions.
4
What type of vulnerability is CVE-2016-9998?
CVE-2016-9998 is a reflected cross-site scripting vulnerability affecting the `$plugin` parameter.
5
Can CVE-2016-9998 lead to data exposure?
Yes, CVE-2016-9998 can lead to data exposure through malicious scripts executed in users' browsers.