PT-2026-20843 · Spip · Spip

Arthur Deloffre

+2

·

Publicado

2026-02-19

·

Atualizado

2026-02-19

·

CVE-2025-71245

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SPIP versions prior to 4.4.8
Description SPIP before version 4.4.8 contains a Cross-Site Scripting (XSS) issue in the private area due to improper handling of iframe tags. The application does not adequately sandbox or escape iframe content within the back-office, which allows an attacker to inject and execute malicious scripts. The vulnerability is not addressed by the SPIP security screen.
Recommendations Update to SPIP version 4.4.8 or later.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-71245

Produtos afetados

Spip