CVE-2022-37155: Code Injection
Published Dec 13, 2022
·Updated
Last updated 4 March 2025
Other sources
RCE in SPIP 3.1.13 through 4.1.2 allows remote authenticated users to execute arbitrary code via the oups parameter.
— MITRE
Affected Software
2 affected componentsFixes available
Spip SPIP>=3.1.13<=4.1.2
debian/spip
3.2.11-3+deb11u103.2.11-3+deb11u74.3.6+dfsg-1
Remediation
Event History
Dec 13, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Dec 14, 2022
Data Sourced
via NVD·12:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Mar 4, 2025
Data Sourced
via Launchpad·02:29 AM
Description
Mar 8, 2025
Data Sourced
via Ubuntu·02:29 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2022-37155?
CVE-2022-37155 is a remote code execution vulnerability in SPIP versions 3.1.13 through 4.1.2.
2
How does CVE-2022-37155 work?
CVE-2022-37155 allows remote authenticated users to execute arbitrary code by exploiting the _oups parameter.
3
What is the severity of CVE-2022-37155?
CVE-2022-37155 has a severity rating of 8.8 (high).
4
Which software versions are affected by CVE-2022-37155?
SPIP versions 3.1.13 through 4.1.2 are affected by CVE-2022-37155.
5
How can I fix CVE-2022-37155?
To fix CVE-2022-37155, update your SPIP installation to version 4.1.5, 4.0.8, or 3.2.16.