CVE-2021-44118Cross-site Scripting in Spip

Severity
5.4MEDIUMNVD
OSV9.8
EPSS
0.3%
top 48.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 26
Latest updateMar 2

Description

SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability. To exploit the vulnerability, a visitor must browse to a malicious SVG file. The vulnerability allows an authenticated attacker to inject malicious code running on the client side into web pages visited by other users (stored XSS).

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages4 packages

debiandebian/spip< spip 3.2.11-3+deb11u1 (bullseye)
Debianspip/spip< 3.2.11-3+deb11u1+2
Ubuntuspip/spip< 3.1.4-4~deb9u5build0.18.04.1+1
NVDspip/spip4.0.0

Patches

🔴Vulnerability Details

4
OSV
spip vulnerabilities2023-03-02
OSV
spip vulnerabilities2022-06-16
GHSA
GHSA-564r-594w-gw2m: SPIP 42022-01-27
OSV
CVE-2021-44118: SPIP 42022-01-26

📋Vendor Advisories

3
Ubuntu
SPIP vulnerabilities2023-03-02
Ubuntu
SPIP vulnerabilities2022-06-16
Debian
CVE-2021-44118: spip - SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability. To exploit...2021
CVE-2021-44118 — Cross-site Scripting in Debian Spip | cvebase