PT-2022-11994 · Spip+2 · Spip+2
Published
2021-12-22
·
Updated
2023-03-02
·
CVE-2021-44118
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SPIP version 4.0.0
Description
The issue allows an authenticated attacker to inject malicious code running on the client side into web pages visited by other users. This is achieved by exploiting a Cross Site Scripting (XSS) vulnerability, where a visitor must browse to a malicious SVG file to trigger the exploit.
Recommendations
For SPIP version 4.0.0, consider disabling the ability to upload or browse to SVG files as a temporary workaround until a patch is available. Restrict access to areas of the application where user-inputted data is displayed to minimize the risk of exploitation.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Spip
Ubuntu