CVE-2025-71240: SPIP < 4.2.15 Cross-Site Scripting via Code Tags
SPIP before 4.2.15 allows Cross-Site Scripting (XSS) via crafted content in HTML code tags. The application does not properly verify JavaScript within code tags, allowing an attacker to inject malicious scripts that execute in a victim's browser.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-71240?
CVE-2025-71240 is considered a high severity Cross-Site Scripting (XSS) vulnerability that can allow an attacker to inject malicious scripts.
How do I fix CVE-2025-71240?
To mitigate CVE-2025-71240, upgrade SPIP to version 4.2.15 or later, which addresses the vulnerability.
What versions of SPIP are affected by CVE-2025-71240?
CVE-2025-71240 affects SPIP versions prior to 4.2.15.
Can CVE-2025-71240 lead to data theft?
Yes, CVE-2025-71240 can allow attackers to execute scripts in victims' browsers, potentially leading to data theft.
Is CVE-2025-71240 a common vulnerability?
CVE-2025-71240 is part of a broader category of XSS vulnerabilities, which are relatively common in web applications.