CVE-2020-28984: Critical severity spip vulnerability
Published Nov 23, 2020
·Updated
prive/formulaires/configurerpreferences.php in SPIP before 3.2.8 does not properly validate the couleur, display, displaynavigation, displayoutils, imessage, and spipecran parameters.
Affected Software
4 affected componentsFixes available
debian/spip
3.2.4-1+deb10u93.2.4-1+deb10u113.2.11-3+deb11u93.2.11-3+deb11u74.1.9+dfsg-1+deb12u24.1.12+dfsg-1
Spip SPIP<3.2.8
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Remediation
Event History
Nov 23, 2020
CVE Published
via MITRE·09:48 PM
Data Sourced
via MITRE·09:48 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-28984?
The severity of CVE-2020-28984 is critical with a CVSS score of 9.8.
2
How does CVE-2020-28984 affect SPIP?
CVE-2020-28984 affects SPIP versions before 3.2.8.
3
Which parameters in prive/formulaires/configurer_preferences.php are not properly validated in CVE-2020-28984?
In CVE-2020-28984, the couleur, display, display_navigation, display_outils, imessage, and spip_ecran parameters in prive/formulaires/configurer_preferences.php are not properly validated.
4
Is Debian Debian Linux affected by CVE-2020-28984?
Yes, Debian Debian Linux versions 9.0 and 10.0 are affected by CVE-2020-28984.
5
How can I fix CVE-2020-28984?
To fix CVE-2020-28984, update SPIP to version 3.2.8 or later.