CVE Vulnerabilities

CVE-2024-8517

Published: Sep 06, 2024 | Modified: Sep 18, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

SPIP before 4.3.2, 4.2.16, and 4.1.18 is vulnerable to a command injection issue. A remote and unauthenticated attacker can execute arbitrary operating system commands by sending a crafted multipart file upload HTTP request.

Affected Software

Name Vendor Start Version End Version
Spip Spip 4.0.0 (including) 4.1.18 (excluding)
Spip Spip 4.2.0 (including) 4.2.15 (including)
Spip Spip 4.3.0 (including) 4.3.0 (including)
Spip Spip 4.3.1 (including) 4.3.1 (including)
Spip Ubuntu upstream *

References