PT-2022-11994 · Spip+2 · Spip+2

Published

2021-12-22

·

Updated

2023-03-02

·

CVE-2021-44118

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SPIP version 4.0.0
Description The issue allows an authenticated attacker to inject malicious code running on the client side into web pages visited by other users. This is achieved by exploiting a Cross Site Scripting (XSS) vulnerability, where a visitor must browse to a malicious SVG file to trigger the exploit.
Recommendations For SPIP version 4.0.0, consider disabling the ability to upload or browse to SVG files as a temporary workaround until a patch is available. Restrict access to areas of the application where user-inputted data is displayed to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-44118
DLA-2867-1
DSA-5028-1
USN-5482-1
USN-5482-2

Affected Products

Linuxmint
Spip
Ubuntu