First published: Mon Feb 27 2023(Updated: )
Last updated 24 July 2024
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Spip | <=4.1.5 | |
debian/spip | 3.2.11-3+deb11u10 3.2.11-3+deb11u7 4.3.6+dfsg-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this SQL injection vulnerability in SPIP is CVE-2023-24258.
SPIP is a content management system.
CVE-2023-24258 has a severity rating of 9.8 (Critical).
An attacker can exploit this vulnerability by sending a crafted POST request with a manipulated _oups parameter to execute arbitrary code.
Yes, patches are available to fix this vulnerability. Please refer to the provided references for more information.