CVE-2019-11071
published 2019-04-10CVE-2019-11071: SPIP 3.1 before 3.1.10 and 3.2 before 3.2.4 allows authenticated visitors to execute arbitrary code on the host server because var_memotri is mishandled.
PriorityP352high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
2.58%
83.5th percentile
SPIP 3.1 before 3.1.10 and 3.2 before 3.2.4 allows authenticated visitors to execute arbitrary code on the host server because var_memotri is mishandled.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | spip | < spip 3.2.4-1 (bullseye) | spip 3.2.4-1 (bullseye) |
| spip | spip | >= 0 < 3.2.4-1 | 3.2.4-1 |
| spip | spip | >= 0 < 3.2.4-1 | 3.2.4-1 |
| spip | spip | >= 0 < 3.2.4-1 | 3.2.4-1 |
| spip | spip | >= 0 < 3.1.4-4~deb9u3build0.18.04.1 | 3.1.4-4~deb9u3build0.18.04.1 |
| spip | spip | >= 3.1.0 < 3.1.10 | 3.1.10 |
| spip | spip | >= 3.2.0 < 3.2.4 | 3.2.4 |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_ubuntu6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v4x3-p383-7f79: SPIP 3
ghsa_unreviewed·2022-05-13
CVE-2019-11071 [HIGH] CWE-20 GHSA-v4x3-p383-7f79: SPIP 3
SPIP 3.1 before 3.1.10 and 3.2 before 3.2.4 allows authenticated visitors to execute arbitrary code on the host server because var_memotri is mishandled.
OSV
spip vulnerabilities
osv·2020-09-24·CVSS 6.1
CVE-2019-16392 [MEDIUM] spip vulnerabilities
spip vulnerabilities
Youssouf Boulouiz discovered that SPIP incorrectly handled login error
messages. A remote attacker could potentially exploit this to conduct
cross-site scripting (XSS) attacks. (CVE-2019-16392)
Gilles Vincent discovered that SPIP incorrectly handled password reset
requests. A remote attacker could possibly use this issue to cause SPIP to
enumerate registered users. (CVE-2019-16394)
Guillaume Fahrner discovered that SPIP did not properly sanitize input. A
remote authenticated attacker could possibly use this issue to execute
arbitrary code on the host server. (CVE-2019-11071)
Sylvain Lefevre discovered that SPIP incorrectly handled user
authorization. A remote attacker could possibly use this issue to modify
and publish content and modify the database. (CVE-2019-163
OSV
CVE-2019-11071: SPIP 3
osv·2019-04-10·CVSS 8.8
CVE-2019-11071 [HIGH] CVE-2019-11071: SPIP 3
SPIP 3.1 before 3.1.10 and 3.2 before 3.2.4 allows authenticated visitors to execute arbitrary code on the host server because var_memotri is mishandled.
Ubuntu
SPIP vulnerabilities
vendor_ubuntu·2020-09-24·CVSS 6.1
CVE-2019-16392 [MEDIUM] SPIP vulnerabilities
Title: SPIP vulnerabilities
Summary: Several security issues were fixed in SPIP.
Youssouf Boulouiz discovered that SPIP incorrectly handled login error
messages. A remote attacker could potentially exploit this to conduct
cross-site scripting (XSS) attacks. (CVE-2019-16392)
Gilles Vincent discovered that SPIP incorrectly handled password reset
requests. A remote attacker could possibly use this issue to cause SPIP to
enumerate registered users. (CVE-2019-16394)
Guillaume Fahrner discovered that SPIP did not properly sanitize input. A
remote authenticated attacker could possibly use this issue to execute
arbitrary code on the host server. (CVE-2019-11071)
Sylvain Lefevre discovered that SPIP incorrectly handled user
authorization. A remote attacker could possibly use this issue to modi
Debian
CVE-2019-11071: spip - SPIP 3.1 before 3.1.10 and 3.2 before 3.2.4 allows authenticated visitors to exe...
vendor_debian·2019·CVSS 8.8
CVE-2019-11071 [HIGH] CVE-2019-11071: spip - SPIP 3.1 before 3.1.10 and 3.2 before 3.2.4 allows authenticated visitors to exe...
SPIP 3.1 before 3.1.10 and 3.2 before 3.2.4 allows authenticated visitors to execute arbitrary code on the host server because var_memotri is mishandled.
Scope: local
bullseye: resolved (fixed in 3.2.4-1)
forky: resolved (fixed in 3.2.4-1)
sid: resolved (fixed in 3.2.4-1)
trixie: resolved (fixed in 3.2.4-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://blog.spip.net/Mise-a-jour-CRITIQUE-de-securite-Sortie-de-SPIP-3-1-10-et-SPIP-3-2-4.htmlhttps://github.com/spip/SPIP/commit/3ef87c525bc0768c926646f999a54222b37b5d36https://github.com/spip/SPIP/commit/824d17f424bf77d17af89c18c3dc807a3199567ehttps://github.com/spip/SPIP/compare/1e3872c...9861a47https://usn.ubuntu.com/4536-1/https://www.debian.org/security/2019/dsa-4429https://blog.spip.net/Mise-a-jour-CRITIQUE-de-securite-Sortie-de-SPIP-3-1-10-et-SPIP-3-2-4.htmlhttps://github.com/spip/SPIP/commit/3ef87c525bc0768c926646f999a54222b37b5d36https://github.com/spip/SPIP/commit/824d17f424bf77d17af89c18c3dc807a3199567ehttps://github.com/spip/SPIP/compare/1e3872c...9861a47https://usn.ubuntu.com/4536-1/https://www.debian.org/security/2019/dsa-4429
2019-04-10
Published