cbcvebase.
CVE-2021-44122
published 2022-01-26

CVE-2021-44122: SPIP 4.0.0 is affected by a Cross Site Request Forgery (CSRF) vulnerability in ecrire/public/aiguiller.php, ecrire/public/balises.php…

PriorityP337high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.49%
39.0th percentile
SPIP 4.0.0 is affected by a Cross Site Request Forgery (CSRF) vulnerability in ecrire/public/aiguiller.php, ecrire/public/balises.php, ecrire/balise/formulaire_.php. To exploit the vulnerability, a visitor must visit a malicious website which redirects to the SPIP website. It is also possible to combine XSS vulnerabilities in SPIP 4.0.0 to exploit it. The vulnerability allows an authenticated attacker to execute malicious code without the knowledge of the user on the website (CSRF).

Affected

7 ranges
VendorProductVersion rangeFixed in
debianspip< spip 3.2.11-3+deb11u1 (bullseye)spip 3.2.11-3+deb11u1 (bullseye)
spipspip
spipspip>= 0 < 3.2.11-3+deb11u13.2.11-3+deb11u1
spipspip>= 0 < 3.2.12-13.2.12-1
spipspip>= 0 < 3.2.12-13.2.12-1
spipspip>= 0 < 3.1.4-4~deb9u5build0.18.04.13.1.4-4~deb9u5build0.18.04.1
spipspip>= 0 < 3.2.7-1ubuntu0.13.2.7-1ubuntu0.1

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.