PT-2026-20848 · Spip · Spip
Dorian Piette
·
Publicado
2026-02-19
·
Atualizado
2026-02-23
·
CVE-2025-71250
CVSS v3.1
8.1
Alta
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SPIP versions prior to 4.4.9
Description
SPIP versions prior to 4.4.9 contain an insecure deserialization flaw. This issue affects the public area through the
table valeur filter and the DATA iterator, which accept serialized data. An attacker who can place malicious serialized content can trigger arbitrary object instantiation and potentially achieve remote code execution. The use of serialized data in these components has been deprecated and will be removed in SPIP 5.Recommendations
Update to SPIP version 4.4.9 or later.
Correção
RCE
Deserialization of Untrusted Data
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Spip