Spip · Spip · CVE-2023-24258
**Name of the Vulnerable Software and Affected Versions**
SPIP versions 4.1.5 and earlier
**Description**
The issue allows attackers to execute arbitrary code via a crafted POST request, exploiting a SQL injection vulnerability through the ` oups` parameter.
**Recommendations**
For SPIP versions 4.1.5 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.