PT-2026-20840 · Spip · Spip

Published

2025-01-01

·

Updated

2026-02-23

·

CVE-2025-71242

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SPIP versions prior to 4.3.6 SPIP versions prior to 4.2.17 SPIP versions prior to 4.1.20
Description The application does not properly verify authorization when displaying content of articles and sections (rubriques) in AJAX-loaded fragments, which allows an authenticated attacker to access restricted content. The SPIP security screen does not mitigate this issue.
Recommendations Update to SPIP version 4.3.6 or later. Update to SPIP version 4.2.17 or later. Update to SPIP version 4.1.20 or later.

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-71242

Affected Products

Spip