Vulnerability Description
SPIP v4.1.5 and earlier was discovered to contain a SQL injection vulnerability via the _oups parameter. This vulnerability allows attackers to execute arbitrary code via a crafted POST request.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Spip | Spip | <= 4.1.5 |
Related Weaknesses (CWE)
References
- https://blog.spip.net/Mise-a-jour-de-securite-sortie-de-SPIP-4-1-7-SPIP-4-0-9-etRelease Notes
- https://github.com/Abyss-W4tcher/ab4yss-wr4iteups/blob/ffa980faa9e3598d49d6fb7deExploitThird Party Advisory
- https://www.debian.org/security/2023/dsa-5325
- https://blog.spip.net/Mise-a-jour-de-securite-sortie-de-SPIP-4-1-7-SPIP-4-0-9-etRelease Notes
- https://github.com/Abyss-W4tcher/ab4yss-wr4iteups/blob/ffa980faa9e3598d49d6fb7deExploitThird Party Advisory
- https://www.debian.org/security/2023/dsa-5325
FAQ
What is CVE-2023-24258?
CVE-2023-24258 is a vulnerability with a CVSS score of 9.8 (CRITICAL). SPIP v4.1.5 and earlier was discovered to contain a SQL injection vulnerability via the _oups parameter. This vulnerability allows attackers to execute arbitrary code via a crafted POST request.
How severe is CVE-2023-24258?
CVE-2023-24258 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-24258?
Check the references section above for vendor advisories and patch information. Affected products include: Spip Spip.