PT-2024-6564 · Spip · Spip+1
Louka Jacques-Chevallier
·
Published
2024-08-19
·
Updated
2025-12-08
·
CVE-2024-7954
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SPIP versions prior to 4.30-alpha2, 4.2.13, and 4.1.16
Description
The porte plume plugin used by SPIP is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can execute arbitrary PHP as the SPIP user by sending a crafted HTTP request.
Recommendations
For SPIP versions prior to 4.30-alpha2, 4.2.13, and 4.1.16, upgrade to a version that is 4.30-alpha2, 4.2.13, or 4.1.16 or later to mitigate the risk of remote exploitation.
As a temporary workaround, consider disabling the porte plume plugin until a patch is available.
Restrict access to the SPIP system to minimize the risk of exploitation.
Exploit
Fix
RCE
Improper Access Control
Eval Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Spip
Porte Plume