CVE-2021-44122
published 2022-01-26CVE-2021-44122: SPIP 4.0.0 is affected by a Cross Site Request Forgery (CSRF) vulnerability in ecrire/public/aiguiller.php, ecrire/public/balises.php…
PriorityP337high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.49%
39.0th percentile
SPIP 4.0.0 is affected by a Cross Site Request Forgery (CSRF) vulnerability in ecrire/public/aiguiller.php, ecrire/public/balises.php, ecrire/balise/formulaire_.php. To exploit the vulnerability, a visitor must visit a malicious website which redirects to the SPIP website. It is also possible to combine XSS vulnerabilities in SPIP 4.0.0 to exploit it. The vulnerability allows an authenticated attacker to execute malicious code without the knowledge of the user on the website (CSRF).
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | spip | < spip 3.2.11-3+deb11u1 (bullseye) | spip 3.2.11-3+deb11u1 (bullseye) |
| spip | spip | — | — |
| spip | spip | >= 0 < 3.2.11-3+deb11u1 | 3.2.11-3+deb11u1 |
| spip | spip | >= 0 < 3.2.12-1 | 3.2.12-1 |
| spip | spip | >= 0 < 3.2.12-1 | 3.2.12-1 |
| spip | spip | >= 0 < 3.1.4-4~deb9u5build0.18.04.1 | 3.1.4-4~deb9u5build0.18.04.1 |
| spip | spip | >= 0 < 3.2.7-1ubuntu0.1 | 3.2.7-1ubuntu0.1 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
spip vulnerabilities
osv·2023-03-02·CVSS 9.8
CVE-2021-44118 [CRITICAL] spip vulnerabilities
spip vulnerabilities
USN-5482-1 fixed several vulnerabilities in SPIP. This update provides
the corresponding updates for Ubuntu 20.04 LTS for CVE-2021-44118,
CVE-2021-44120, CVE-2021-44122 and CVE-2021-44123.
Original advisory details:
It was discovered that SPIP incorrectly validated inputs. An authenticated
attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 18.04 LTS. (CVE-2020-28984)
Charles Fol and Théo Gordyjan discovered that SPIP is vulnerable to Cross
Site Scripting (XSS). If a user were tricked into browsing a malicious SVG
file, an attacker could possibly exploit this issue to execute arbitrary
code. This issue was only fixed in Ubuntu 21.10. (CVE-2021-44118,
CVE-2021-44120, CVE-2021-44122, CVE-2021-44123)
It was discovered th
OSV
spip vulnerabilities
osv·2022-06-16·CVSS 9.8
CVE-2020-28984 [CRITICAL] spip vulnerabilities
spip vulnerabilities
It was discovered that SPIP incorrectly validated inputs. An authenticated
attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 18.04 LTS. (CVE-2020-28984)
Charles Fol and Théo Gordyjan discovered that SPIP is vulnerable to Cross
Site Scripting (XSS). If a user were tricked into browsing a malicious SVG
file, an attacker could possibly exploit this issue to execute arbitrary
code. This issue was only fixed in Ubuntu 21.10. (CVE-2021-44118,
CVE-2021-44120, CVE-2021-44122, CVE-2021-44123)
It was discovered that SPIP incorrectly handled certain forms. A remote
authenticated editor could possibly use this issue to execute arbitrary code,
and a remote unauthenticated attacker could possibly use this issue to obtain
sensitive i
GHSA
GHSA-fv46-9fmf-2p7g: SPIP 4
ghsa_unreviewed·2022-01-27
CVE-2021-44122 [HIGH] CWE-352 GHSA-fv46-9fmf-2p7g: SPIP 4
SPIP 4.0.0 is affected by a Cross Site Request Forgery (CSRF) vulnerability in ecrire/public/aiguiller.php, ecrire/public/balises.php, ecrire/balise/formulaire_.php. To exploit the vulnerability, a visitor must visit a malicious website which redirects to the SPIP website. It is also possible to combine XSS vulnerabilities in SPIP 4.0.0 to exploit it. The vulnerability allows an authenticated attacker to execute malicious code without the knowledge of the user on the website (CSRF).
OSV
CVE-2021-44122: SPIP 4
osv·2022-01-26·CVSS 8.8
CVE-2021-44122 [HIGH] CVE-2021-44122: SPIP 4
SPIP 4.0.0 is affected by a Cross Site Request Forgery (CSRF) vulnerability in ecrire/public/aiguiller.php, ecrire/public/balises.php, ecrire/balise/formulaire_.php. To exploit the vulnerability, a visitor must visit a malicious website which redirects to the SPIP website. It is also possible to combine XSS vulnerabilities in SPIP 4.0.0 to exploit it. The vulnerability allows an authenticated attacker to execute malicious code without the knowledge of the user on the website (CSRF).
Ubuntu
SPIP vulnerabilities
vendor_ubuntu·2023-03-02·CVSS 9.8
CVE-2021-44118 [CRITICAL] SPIP vulnerabilities
Title: SPIP vulnerabilities
Summary: Several security issues were fixed in SPIP.
USN-5482-1 fixed several vulnerabilities in SPIP. This update provides
the corresponding updates for Ubuntu 20.04 LTS for CVE-2021-44118,
CVE-2021-44120, CVE-2021-44122 and CVE-2021-44123.
Original advisory details:
It was discovered that SPIP incorrectly validated inputs. An authenticated
attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 18.04 LTS. (CVE-2020-28984)
Charles Fol and Théo Gordyjan discovered that SPIP is vulnerable to Cross
Site Scripting (XSS). If a user were tricked into browsing a malicious SVG
file, an attacker could possibly exploit this issue to execute arbitrary
code. This issue was only fixed in Ubuntu 21.10. (CVE-2021-44118,
CVE-2021
Ubuntu
SPIP vulnerabilities
vendor_ubuntu·2022-06-16·CVSS 9.8
CVE-2021-44123 [CRITICAL] SPIP vulnerabilities
Title: SPIP vulnerabilities
Summary: Several security issues were fixed in SPIP.
It was discovered that SPIP incorrectly validated inputs. An authenticated
attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 18.04 LTS. (CVE-2020-28984)
Charles Fol and Théo Gordyjan discovered that SPIP is vulnerable to Cross
Site Scripting (XSS). If a user were tricked into browsing a malicious SVG
file, an attacker could possibly exploit this issue to execute arbitrary
code. This issue was only fixed in Ubuntu 21.10. (CVE-2021-44118,
CVE-2021-44120, CVE-2021-44122, CVE-2021-44123)
It was discovered that SPIP incorrectly handled certain forms. A remote
authenticated editor could possibly use this issue to execute arbitrary code,
and a remote unauthenticated
Debian
CVE-2021-44122: spip - SPIP 4.0.0 is affected by a Cross Site Request Forgery (CSRF) vulnerability in e...
vendor_debian·2021·CVSS 8.8
CVE-2021-44122 [HIGH] CVE-2021-44122: spip - SPIP 4.0.0 is affected by a Cross Site Request Forgery (CSRF) vulnerability in e...
SPIP 4.0.0 is affected by a Cross Site Request Forgery (CSRF) vulnerability in ecrire/public/aiguiller.php, ecrire/public/balises.php, ecrire/balise/formulaire_.php. To exploit the vulnerability, a visitor must visit a malicious website which redirects to the SPIP website. It is also possible to combine XSS vulnerabilities in SPIP 4.0.0 to exploit it. The vulnerability allows an authenticated attacker to execute malicious code without the knowledge of the user on the website (CSRF).
Scope: local
bullseye: resolved (fixed in 3.2.11-3+deb11u1)
forky: resolved (fixed in 3.2.12-1)
sid: resolved (fixed in 3.2.12-1)
trixie: resolved (fixed in 3.2.12-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-01-26
Published