PT-2024-6564 · Spip · Spip+1

Louka Jacques-Chevallier

·

Published

2024-08-19

·

Updated

2025-12-08

·

CVE-2024-7954

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SPIP versions prior to 4.30-alpha2, 4.2.13, and 4.1.16
Description The porte plume plugin used by SPIP is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can execute arbitrary PHP as the SPIP user by sending a crafted HTTP request.
Recommendations For SPIP versions prior to 4.30-alpha2, 4.2.13, and 4.1.16, upgrade to a version that is 4.30-alpha2, 4.2.13, or 4.1.16 or later to mitigate the risk of remote exploitation. As a temporary workaround, consider disabling the porte plume plugin until a patch is available. Restrict access to the SPIP system to minimize the risk of exploitation.

Exploit

Fix

RCE

Improper Access Control

Eval Injection

Weakness Enumeration

Related Identifiers

BDU:2024-07708
CVE-2024-7954

Affected Products

Spip
Porte Plume