SPIP before 3.1.11 and 3.2 before 3.2.5 allows authenticated visitors to modify any published content and execute other modifications in the database. This is related to ecrire/inc/meta.php and ecrire/inc/securiser_action.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Spip | Spip | * | 3.1.11 (excluding) |
Spip | Spip | 3.2.0 (including) | 3.2.5 (excluding) |
Spip | Ubuntu | bionic | * |
Spip | Ubuntu | disco | * |
Spip | Ubuntu | eoan | * |
Spip | Ubuntu | esm-apps/xenial | * |
Spip | Ubuntu | trusty | * |
Spip | Ubuntu | upstream | * |
Spip | Ubuntu | xenial | * |