CVE-2023-24258: SQL Injection
Published Feb 27, 2023
·Updated
Last updated 4 March 2025
Other sources
SPIP v4.1.5 and earlier was discovered to contain a SQL injection vulnerability via the oups parameter. This vulnerability allows attackers to execute arbitrary code via a crafted POST request.
Affected Software
2 affected componentsFixes available
Spip SPIP<=4.1.5
debian/spip
3.2.11-3+deb11u103.2.11-3+deb11u74.3.6+dfsg-1
Event History
Feb 27, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Mar 4, 2025
Data Sourced
via Launchpad·02:29 AM
Description
Mar 8, 2025
Data Sourced
via Ubuntu·02:29 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this SQL injection vulnerability in SPIP?
The vulnerability ID for this SQL injection vulnerability in SPIP is CVE-2023-24258.
2
What is SPIP?
SPIP is a content management system.
3
What is the severity rating of CVE-2023-24258?
CVE-2023-24258 has a severity rating of 9.8 (Critical).
4
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by sending a crafted POST request with a manipulated _oups parameter to execute arbitrary code.
5
Are there any patches available to fix this vulnerability?
Yes, patches are available to fix this vulnerability. Please refer to the provided references for more information.