CVE-2022-28960: High severity spip vulnerability
Published May 19, 2022
·Updated
A PHP injection vulnerability in Spip before v3.2.8 allows attackers to execute arbitrary PHP code via the oups parameter at /ecrire.
Affected Software
2 affected componentsFixes available
Spip SPIP<3.2.8
debian/spip
3.2.11-3+deb11u103.2.11-3+deb11u74.3.6+dfsg-1
Remediation
Event History
May 19, 2022
CVE Published
via MITRE·08:26 PM
Data Sourced
via MITRE·08:26 PM
Description
Mar 4, 2025
Data Sourced
via Launchpad·02:29 AM
Description
Mar 8, 2025
Data Sourced
via Ubuntu·02:29 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2022-28960?
CVE-2022-28960 is a PHP injection vulnerability in Spip before v3.2.8 that allows attackers to execute arbitrary PHP code via the _oups parameter at /ecrire.
2
What software is affected by CVE-2022-28960?
Spip versions before v3.2.8 are affected by CVE-2022-28960.
3
How severe is CVE-2022-28960?
CVE-2022-28960 has a severity level of 8.8 (high).
4
How can I fix CVE-2022-28960?
To fix CVE-2022-28960, update Spip to version 3.2.8 or higher.
5
Where can I find more information about CVE-2022-28960?
You can find more information about CVE-2022-28960 in the following references: [link1], [link2], [link3].