CVE-2023-27372

SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:spip:spip:4.2.0:alpha2:*:*:*:*:*:*
cpe:2.3:a:spip:spip:4.2.0:alpha:*:*:*:*:*:*
cpe:2.3:a:spip:spip:4.2.0:-:*:*:*:*:*:*
cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

Information

Published : 2023-02-28 12:15

Updated : 2023-03-06 08:26


NVD link : CVE-2023-27372

Mitre link : CVE-2023-27372


JSON object : View

Advertisement

dedicated server usa

Products Affected

debian

  • debian_linux

spip

  • spip