CVE-2024-8517: SPIP Bigup Multipart File Upload OS Command Injection
Published Sep 6, 2024
·Updated
Last updated 4 March 2025
Other sources
SPIP before 4.3.2, 4.2.16, and 4.1.18 is vulnerable to a command injection issue. A remote and unauthenticated attacker can execute arbitrary operating system commands by sending a crafted multipart file upload HTTP request.
— MITRE
Affected Software
5 affected componentsFixes available
Spip SPIP>=4.0.0<4.1.18
Spip SPIP>=4.2.0<=4.2.15
Spip SPIP=4.3.0
Spip SPIP=4.3.1
debian/spip
3.2.11-3+deb11u103.2.11-3+deb11u74.3.6+dfsg-1
Event History
Sep 6, 2024
CVE Published
via MITRE·03:55 PM
Data Sourced
via MITRE·03:55 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Mar 8, 2025
Data Sourced
via Ubuntu·02:29 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-8517?
CVE-2024-8517 has a high severity rating due to its potential for remote code execution.
2
How do I fix CVE-2024-8517?
To fix CVE-2024-8517, upgrade SPIP to versions 4.3.2, 4.2.16, or 4.1.18 or later.
3
Who is affected by CVE-2024-8517?
CVE-2024-8517 affects all SPIP versions prior to 4.3.2, 4.2.16, and 4.1.18.
4
What type of vulnerability is CVE-2024-8517?
CVE-2024-8517 is a command injection vulnerability allowing attackers to execute arbitrary operating system commands.
5
Can CVE-2024-8517 be exploited remotely?
Yes, CVE-2024-8517 can be exploited remotely by unauthenticated attackers through crafted multipart file uploads.