CVE Vulnerabilities

CVE-2022-37155

Published: Dec 14, 2022 | Modified: Jan 30, 2023
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

RCE in SPIP 3.1.13 through 4.1.2 allows remote authenticated users to execute arbitrary code via the _oups parameter.

Affected Software

Name Vendor Start Version End Version
Spip Spip 3.1.13 (including) 4.1.2 (including)
Spip Ubuntu bionic *
Spip Ubuntu kinetic *
Spip Ubuntu lunar *
Spip Ubuntu mantic *
Spip Ubuntu trusty *
Spip Ubuntu xenial *

References