CVE-2019-19830: Medium severity Spip SPIP vulnerability
Published Dec 17, 2019
·Updated
core/plugins/medias in SPIP 3.2.x before 3.2.7 allows remote authenticated authors to inject content into the database.
Affected Software
5 affected componentsFixes available
Spip SPIP>=3.2.0<3.2.7
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Canonical Ubuntu Linux=18.04
debian/spip
3.2.11-3+deb11u103.2.11-3+deb11u74.4.3+dfsg-1+deb13u14.4.8+dfsg-14.4.9+dfsg-1
Remediation
Event History
Dec 17, 2019
CVE Published
via MITRE·04:33 AM
Data Sourced
via MITRE·04:33 AM
Description
Data Sourced
via NVD·05:15 AM
RemedyDescriptionSeverityAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·11:25 PM
Description
Feb 19, 2026
Data Sourced
via Ubuntu·09:29 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·09:30 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2019-19830.
2
What is the severity of CVE-2019-19830?
The severity of CVE-2019-19830 is medium.
3
What is the affected software?
SPIP versions 3.2.x before 3.2.7, SPIP versions 3.1.4-4~ and SPIP versions 3.2.7-1 on Ubuntu are affected.
4
How can remote authenticated authors exploit this vulnerability?
Remote authenticated authors can inject content into the database.
5
How can I fix CVE-2019-19830?
Update SPIP to version 3.2.7 or apply the appropriate remedy for your specific package/source.