PT-2026-21859 · WordPress · Spip Tickets Plugin
Valentin Lobstein
+1
·
Publicado
2026-02-25
·
Atualizado
2026-03-02
·
CVE-2026-27744
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SPIP tickets plugin versions prior to 4.3.3
Description
The SPIP tickets plugin is affected by a remote code execution issue. An unauthenticated attacker can execute code on the web server through crafted content injection. The plugin appends untrusted request parameters into HTML that is rendered by a template using unfiltered environment rendering (
#ENV), disabling SPIP output filtering. This allows the attacker to inject content that is evaluated by SPIP’s template processing chain.Recommendations
Update the SPIP tickets plugin to version 4.3.3 or later.
Exploit
Correção
RCE
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Spip Tickets Plugin