CVE-2019-16393: Medium severity Spip SPIP vulnerability
Published Sep 17, 2019
·Updated
Last updated 26 August 2025
Other sources
SPIP before 3.1.11 and 3.2 before 3.2.5 mishandles redirect URLs in ecrire/inc/headers.php with a %0D, %0A, or %20 character.
— Launchpad
Affected Software
7 affected componentsFixes available
Spip SPIP<3.1.11
Spip SPIP>=3.2.0<3.2.5
Canonical Ubuntu Linux=18.04
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0
debian/spip
3.2.11-3+deb11u103.2.11-3+deb11u74.4.3+dfsg-1+deb13u14.4.8+dfsg-14.4.9+dfsg-1
Remediation
Event History
Sep 17, 2019
CVE Published
via MITRE·08:48 PM
Data Sourced
via MITRE·08:48 PM
Description
Data Sourced
via NVD·09:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·11:22 PM
Description
Feb 19, 2026
Data Sourced
via Ubuntu·09:29 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·09:30 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this SPIP vulnerability?
The vulnerability ID for this SPIP vulnerability is CVE-2019-16393.
2
What is the severity rating of CVE-2019-16393?
CVE-2019-16393 has a severity rating of 6.1 (medium).
3
What software versions are affected by CVE-2019-16393?
SPIP versions before 3.1.11 and 3.2 before 3.2.5 are affected by CVE-2019-16393.
4
How does CVE-2019-16393 impact SPIP?
CVE-2019-16393 can cause mishandling of redirect URLs in SPIP, specifically in the ecrire/inc/headers.php file.
5
How can I fix CVE-2019-16393?
To fix CVE-2019-16393, you should update SPIP to version 3.1.11 or 3.2.5 or later, as provided by the official sources.