CVE-2024-7954: SPIP porte_plume Plugin Arbitrary PHP Execution
Published Aug 23, 2024
·Updated
The porteplume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can execute arbitrary PHP as the SPIP user by sending a crafted HTTP request.
Affected Software
1 affected component
Spip porte_plume Plugin<4.30-alpha2, <4.2.13, <4.1.16
Event History
Aug 23, 2024
CVE Published
via MITRE·05:43 PM
Data Sourced
via MITRE·05:43 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Jul 4, 56726
Event
via FIRST·01:15 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-7954?
CVE-2024-7954 is classified as a critical vulnerability that allows arbitrary code execution.
2
How do I fix CVE-2024-7954?
To fix CVE-2024-7954, you should upgrade the porte_plume plugin to a version newer than 4.30-alpha2, 4.2.13, or 4.1.16.
3
Who is affected by CVE-2024-7954?
CVE-2024-7954 affects users of the porte_plume plugin in SPIP versions prior to 4.30-alpha2, 4.2.13, and 4.1.16.
4
What type of attack does CVE-2024-7954 enable?
CVE-2024-7954 enables remote and unauthenticated attackers to execute arbitrary PHP code.
5
Can CVE-2024-7954 be exploited without authentication?
Yes, CVE-2024-7954 can be exploited by remote attackers without authentication.