CVE-2023-27372
Published Feb 28, 2023
Last updated a year ago
Overview
- Description
- SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
Weaknesses
- nvd@nist.gov
- NVD-CWE-noinfo
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FF6C248E-6246-469B-858D-DB628B535BDA", "versionEndExcluding": "3.2.18" }, { "criteria": "cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A67A687F-6F6C-4150-92BB-90A308B89B4A", "versionEndExcluding": "4.0.10", "versionStartIncluding": "4.0.0" }, { "criteria": "cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4188B203-546F-4EE3-AD33-A31F3AF16B76", "versionEndExcluding": "4.1.8", "versionStartIncluding": "4.1.0" }, { "criteria": "cpe:2.3:a:spip:spip:4.2.0:-:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D55ECBAF-CDAB-4F7E-9BD1-BD9178732934" }, { "criteria": "cpe:2.3:a:spip:spip:4.2.0:alpha:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1CED71D6-E720-4007-BEE3-B81CC4F5EDD2" }, { "criteria": "cpe:2.3:a:spip:spip:4.2.0:alpha2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0746C763-3FD4-4095-9F1C-9BEAE6E6E29B" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FA6FEEC2-9F11-4643-8827-749718254FED" } ], "operator": "OR" } ] } ]