PT-2024-35793 · Spip · Spip

Published

2024-11-26

·

Updated

2024-11-26

·

CVE-2024-53619

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions SPIP version 4.3.3
Description The issue concerns an authenticated arbitrary file upload vulnerability in the Documents module. This allows attackers to execute arbitrary code by uploading a crafted PDF file. There is no information provided about the estimated number of potentially affected devices worldwide or details about real-world incidents where this issue was exploited.
Recommendations For SPIP version 4.3.3, consider disabling the file upload feature in the Documents module until a patch is available. Restrict access to the Documents module to minimize the risk of exploitation. Avoid using the file upload functionality with crafted PDF files until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-53619

Affected Products

Spip