CVE-2019-16391
published 2019-09-17CVE-2019-16391: SPIP before 3.1.11 and 3.2 before 3.2.5 allows authenticated visitors to modify any published content and execute other modifications in the database. This is…
PriorityP336medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
EPSS
1.49%
71.2th percentile
SPIP before 3.1.11 and 3.2 before 3.2.5 allows authenticated visitors to modify any published content and execute other modifications in the database. This is related to ecrire/inc/meta.php and ecrire/inc/securiser_action.php.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | spip | < spip 3.2.5-1 (bullseye) | spip 3.2.5-1 (bullseye) |
| spip | spip | < 3.1.11 | 3.1.11 |
| spip | spip | >= 0 < 3.2.5-1 | 3.2.5-1 |
| spip | spip | >= 0 < 3.2.5-1 | 3.2.5-1 |
| spip | spip | >= 0 < 3.2.5-1 | 3.2.5-1 |
| spip | spip | >= 0 < 3.1.4-4~deb9u3build0.18.04.1 | 3.1.4-4~deb9u3build0.18.04.1 |
| spip | spip | >= 3.2.0 < 3.2.5 | 3.2.5 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_ubuntu6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-ff33-vc6x-7mcf: SPIP before 3
ghsa_unreviewed·2022-05-24
CVE-2019-16391 [MEDIUM] GHSA-ff33-vc6x-7mcf: SPIP before 3
SPIP before 3.1.11 and 3.2 before 3.2.5 allows authenticated visitors to modify any published content and execute other modifications in the database. This is related to ecrire/inc/meta.php and ecrire/inc/securiser_action.php.
OSV
spip vulnerabilities
osv·2020-09-24·CVSS 6.1
CVE-2019-16392 [MEDIUM] spip vulnerabilities
spip vulnerabilities
Youssouf Boulouiz discovered that SPIP incorrectly handled login error
messages. A remote attacker could potentially exploit this to conduct
cross-site scripting (XSS) attacks. (CVE-2019-16392)
Gilles Vincent discovered that SPIP incorrectly handled password reset
requests. A remote attacker could possibly use this issue to cause SPIP to
enumerate registered users. (CVE-2019-16394)
Guillaume Fahrner discovered that SPIP did not properly sanitize input. A
remote authenticated attacker could possibly use this issue to execute
arbitrary code on the host server. (CVE-2019-11071)
Sylvain Lefevre discovered that SPIP incorrectly handled user
authorization. A remote attacker could possibly use this issue to modify
and publish content and modify the database. (CVE-2019-163
OSV
CVE-2019-16391: SPIP before 3
osv·2019-09-17·CVSS 6.5
CVE-2019-16391 [MEDIUM] CVE-2019-16391: SPIP before 3
SPIP before 3.1.11 and 3.2 before 3.2.5 allows authenticated visitors to modify any published content and execute other modifications in the database. This is related to ecrire/inc/meta.php and ecrire/inc/securiser_action.php.
Ubuntu
SPIP vulnerabilities
vendor_ubuntu·2020-09-24·CVSS 6.1
CVE-2019-16392 [MEDIUM] SPIP vulnerabilities
Title: SPIP vulnerabilities
Summary: Several security issues were fixed in SPIP.
Youssouf Boulouiz discovered that SPIP incorrectly handled login error
messages. A remote attacker could potentially exploit this to conduct
cross-site scripting (XSS) attacks. (CVE-2019-16392)
Gilles Vincent discovered that SPIP incorrectly handled password reset
requests. A remote attacker could possibly use this issue to cause SPIP to
enumerate registered users. (CVE-2019-16394)
Guillaume Fahrner discovered that SPIP did not properly sanitize input. A
remote authenticated attacker could possibly use this issue to execute
arbitrary code on the host server. (CVE-2019-11071)
Sylvain Lefevre discovered that SPIP incorrectly handled user
authorization. A remote attacker could possibly use this issue to modi
Debian
CVE-2019-16391: spip - SPIP before 3.1.11 and 3.2 before 3.2.5 allows authenticated visitors to modify ...
vendor_debian·2019·CVSS 6.5
CVE-2019-16391 [MEDIUM] CVE-2019-16391: spip - SPIP before 3.1.11 and 3.2 before 3.2.5 allows authenticated visitors to modify ...
SPIP before 3.1.11 and 3.2 before 3.2.5 allows authenticated visitors to modify any published content and execute other modifications in the database. This is related to ecrire/inc/meta.php and ecrire/inc/securiser_action.php.
Scope: local
bullseye: resolved (fixed in 3.2.5-1)
forky: resolved (fixed in 3.2.5-1)
sid: resolved (fixed in 3.2.5-1)
trixie: resolved (fixed in 3.2.5-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://blog.spip.net/Mise-a-jour-CRITIQUE-de-securite-Sortie-de-SPIP-3-2-5-et-SPIP-3-1-11.htmlhttps://blog.spip.net/Mise-a-jour-CRITIQUE-de-securite-Sortie-de-SPIP-3-2-5-et-SPIP-3-1-11.html?lang=frhttps://git.spip.net/SPIP/spip/commit/187952ce85e73b52c2753f2d54fc2c44807b8f79https://git.spip.net/SPIP/spip/commit/3cbc758400323ab006c00ea78eacdb8f76aa5f66https://lists.debian.org/debian-lts-announce/2019/10/msg00038.htmlhttps://seclists.org/bugtraq/2019/Sep/40https://usn.ubuntu.com/4536-1/https://www.debian.org/security/2019/dsa-4532https://blog.spip.net/Mise-a-jour-CRITIQUE-de-securite-Sortie-de-SPIP-3-2-5-et-SPIP-3-1-11.htmlhttps://blog.spip.net/Mise-a-jour-CRITIQUE-de-securite-Sortie-de-SPIP-3-2-5-et-SPIP-3-1-11.html?lang=frhttps://git.spip.net/SPIP/spip/commit/187952ce85e73b52c2753f2d54fc2c44807b8f79https://git.spip.net/SPIP/spip/commit/3cbc758400323ab006c00ea78eacdb8f76aa5f66https://lists.debian.org/debian-lts-announce/2019/10/msg00038.htmlhttps://seclists.org/bugtraq/2019/Sep/40https://usn.ubuntu.com/4536-1/https://www.debian.org/security/2019/dsa-4532
2019-09-17
Published