SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability. To exploit the vulnerability, a visitor must browse to a malicious SVG file. The vulnerability allows an authenticated attacker to inject malicious code running on the client side into web pages visited by other users (stored XSS).
References
Link | Resource |
---|---|
https://git.spip.net/spip/medias/commit/13c293fabd35e2c152379522c29432423936cbba | Patch Third Party Advisory |
https://git.spip.net/spip/spip/commit/4ccf90a6912d7fab97e1bd5619770c9236cc7357 | Patch Third Party Advisory |
https://git.spip.net/spip/spip/commit/1cf91def15966406ddd0488cf9d1ecd1ae82d47a | Patch Third Party Advisory |
Configurations
Information
Published : 2022-01-26 04:15
Updated : 2022-02-01 11:46
NVD link : CVE-2021-44118
Mitre link : CVE-2021-44118
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
spip
- spip