CVE-2025-71242: SPIP < 4.3.6 Authorization Bypass Leading to Content Disclosure
SPIP before 4.3.6, 4.2.17, and 4.1.20 allows unauthorized content disclosure in the private area. The application does not properly check authorization when displaying content of articles and sections (rubriques) in AJAX-loaded fragments, allowing an authenticated attacker to access restricted content. This vulnerability is not mitigated by the SPIP security screen.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-71242?
CVE-2025-71242 has a severity rating of medium due to the potential for unauthorized content disclosure.
How do I fix CVE-2025-71242?
To fix CVE-2025-71242, update SPIP to version 4.3.6 or later, or 4.2.17 and 4.1.20 with the necessary patches.
What impact does CVE-2025-71242 have on my SPIP installation?
CVE-2025-71242 can lead to unauthorized access to restricted content in the private area of SPIP.
Who is affected by CVE-2025-71242?
CVE-2025-71242 affects all SPIP installations prior to versions 4.3.6, 4.2.17, and 4.1.20.
Is authentication required for the exploitation of CVE-2025-71242?
Yes, an attacker must be authenticated in order to exploit CVE-2025-71242 and gain unauthorized access to restricted content.