PT-2026-20845 · Spip · Spip

Dorian Piette

·

Publicado

2026-02-19

·

Atualizado

2026-02-23

·

CVE-2025-71247

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions SPIP versions prior to 4.4.9
Description SPIP before version 4.4.9 contains a Blind Server-Side Request Forgery (SSRF) issue related to syndicated sites within the private area. The application does not validate the syndication URL when editing a syndicated site, potentially allowing an authenticated attacker to force the server to make requests to arbitrary internal or external destinations. The SPIP security screen does not mitigate this issue.
Recommendations Update to SPIP version 4.4.9 or later.

Correção

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-71247

Produtos afetados

Spip