CVE-2024-23659: XSS
Published Jan 19, 2024
·Updated
SPIP before 4.1.14 and 4.2.x before 4.2.8 allows XSS via the name of an uploaded file. This is related to javascript/bigup.js and javascript/bigup.utils.js.
Affected Software
2 affected components
Spip SPIP<4.1.14
Spip SPIP>=4.2.0<4.2.8
Remediation
Event History
Jan 19, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-23659?
CVE-2024-23659 is classified as a moderate severity vulnerability due to the potential for cross-site scripting (XSS).
2
How do I fix CVE-2024-23659?
To fix CVE-2024-23659, update your SPIP installation to version 4.1.14 or 4.2.8 or later.
3
What type of vulnerability is CVE-2024-23659?
CVE-2024-23659 is a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts via uploaded file names.
4
Which versions of SPIP are affected by CVE-2024-23659?
CVE-2024-23659 affects SPIP versions prior to 4.1.14 and versions in the 4.2.x branch prior to 4.2.8.
5
What components are involved in CVE-2024-23659?
CVE-2024-23659 is related to the javascript files bigup.js and bigup.utils.js.