PT-2019-4103 · Spip+1 · Spip+1

Published

2019-09-17

·

Updated

2022-05-03

·

CVE-2019-16394

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions SPIP versions prior to 3.1.11 SPIP versions 3.2 prior to 3.2.5
Description The issue is related to the disclosure of user information. It might allow a remote attacker to gain unauthorized access to information. The problem is associated with different error messages provided by the password-reminder page, depending on whether an e-mail address exists, which could help attackers enumerate subscribers.
Recommendations For SPIP versions prior to 3.1.11, update to version 3.1.11 or later. For SPIP versions 3.2 prior to 3.2.5, update to version 3.2.5 or later.

Exploit

Fix

Information Disclosure

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-04672
CVE-2019-16394
DLA-1975-1
DSA-4532-1
USN-4536-1

Affected Products

Spip
Ubuntu