PT-2026-21860 · Spip · Spip+1
Valentin Lobstein
+1
·
Publicado
2026-02-25
·
Atualizado
2026-03-02
·
CVE-2026-27745
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SPIP interface traduction objets plugin versions prior to 2.2.2
SPIP interface traduction objets plugin versions 2.2.2 through 4.3.3
Description
The SPIP interface traduction objets plugin contains an authenticated remote code execution issue in the translation interface workflow. The plugin incorporates untrusted request data into a hidden form field that is rendered without SPIP output filtering. Fields prefixed with an underscore bypass protection mechanisms, and the hidden content is rendered with filtering disabled. This allows an authenticated attacker with editor-level privileges to inject crafted content that is evaluated through SPIP's template processing chain, resulting in code execution in the context of the web server.
Recommendations
Update the SPIP interface traduction objets plugin to version 2.2.2 or later.
Update the SPIP interface traduction objets plugin to version 4.3.3 or later.
Exploit
Correção
RCE
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Spip
Interface Traduction Objets