PT-2024-20008 · Spip · Spip

Daniel Barros

·

Published

2024-01-18

·

Updated

2024-01-25

·

CVE-2024-23659

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SPIP versions prior to 4.1.14 SPIP versions 4.2.x prior to 4.2.8
Description The issue allows for XSS via the name of an uploaded file, related to javascript/bigup.js and javascript/bigup.utils.js.
Recommendations For SPIP versions prior to 4.1.14, update to version 4.1.14 or later. For SPIP versions 4.2.x prior to 4.2.8, update to version 4.2.8 or later. As a temporary workaround, consider restricting the upload of files with potentially malicious names until a patch is available.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-23659

Affected Products

Spip