CVE-2012-2151Cross-site Scripting in Spip

Severity
10.0CRITICALNVD
NVD4.3OSV4.3
EPSS
0.6%
top 31.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 14
Latest updateMay 17

Description

Multiple cross-site scripting (XSS) vulnerabilities in SPIP 1.9.x before 1.9.2.o, 2.0.x before 2.0.18, and 2.1.x before 2.1.13 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

debiandebian/spip< spip 2.1.13-1 (bullseye)
Debianspip/spip< 2.1.13-1+2
NVDspip/spip5 versions+4

🔴Vulnerability Details

4
GHSA
GHSA-2phr-4qpj-wc46: Multiple unspecified vulnerabilities in SPIP before 12022-05-17
GHSA
GHSA-j9xm-57c9-67cv: Multiple cross-site scripting (XSS) vulnerabilities in SPIP 12022-05-17
OSV
CVE-2012-4331: Multiple unspecified vulnerabilities in SPIP before 12012-08-14
OSV
CVE-2012-2151: Multiple cross-site scripting (XSS) vulnerabilities in SPIP 12012-08-14

📋Vendor Advisories

2
Debian
CVE-2012-4331: spip - Multiple unspecified vulnerabilities in SPIP before 1.9.2.o, 2.0.x before 2.0.18...2012
Debian
CVE-2012-2151: spip - Multiple cross-site scripting (XSS) vulnerabilities in SPIP 1.9.x before 1.9.2.o...2012
CVE-2012-2151 — Cross-site Scripting in Debian Spip | cvebase