CVE-2023-24258
published 2023-02-27CVE-2023-24258: SPIP v4.1.5 and earlier was discovered to contain a SQL injection vulnerability via the _oups parameter. This vulnerability allows attackers to execute…
PriorityP352critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.57%
72.6th percentile
SPIP v4.1.5 and earlier was discovered to contain a SQL injection vulnerability via the _oups parameter. This vulnerability allows attackers to execute arbitrary code via a crafted POST request.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | spip | < spip 3.2.11-3+deb11u6 (bullseye) | spip 3.2.11-3+deb11u6 (bullseye) |
| spip | spip | <= 4.1.5 | — |
| spip | spip | >= 0 < 3.2.11-3+deb11u6 | 3.2.11-3+deb11u6 |
| spip | spip | >= 0 < 4.1.7+dfsg-1 | 4.1.7+dfsg-1 |
| spip | spip | >= 0 < 4.1.7+dfsg-1 | 4.1.7+dfsg-1 |
| spip | spip | >= 0 < 3.1.4-4~deb9u5ubuntu0.1~esm2 | 3.1.4-4~deb9u5ubuntu0.1~esm2 |
| spip | spip | >= 0 < 3.2.7-1ubuntu0.1+esm2 | 3.2.7-1ubuntu0.1+esm2 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_ubuntu6.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
spip vulnerabilities
osv·2025-03-04·CVSS 6.1
CVE-2022-23638 [MEDIUM] spip vulnerabilities
spip vulnerabilities
It was discovered that svg-sanitizer, vendored in SPIP, did not properly
sanitize SVG/XML content. An attacker could possibly use this issue to
perform cross site scripting. This issue only affected Ubuntu 24.10.
(CVE-2022-23638)
It was discovered that SPIP did not properly sanitize certain inputs. A
remote attacker could possibly use this issue to perform cross site
scripting. This issue only affected Ubuntu 18.04 LTS. (CVE-2022-28959)
It was discovered that SPIP did not properly sanitize certain inputs. A
remote attacker could possibly use this issue to perform PHP injection
attacks. This issue only affected Ubuntu 18.04 LTS. (CVE-2022-28960)
It was discovered that SPIP did not properly sanitize certain inputs. A
remote attacker could possibly use this issue to p
GHSA
GHSA-9xqm-m59j-x893: SPIP v4
ghsa_unreviewed·2023-02-27
CVE-2023-24258 [CRITICAL] CWE-89 GHSA-9xqm-m59j-x893: SPIP v4
SPIP v4.1.5 and earlier was discovered to contain a SQL injection vulnerability via the _oups parameter. This vulnerability allows attackers to execute arbitrary code via a crafted POST request.
OSV
CVE-2023-24258: SPIP v4
osv·2023-02-27·CVSS 9.8
CVE-2023-24258 [CRITICAL] CVE-2023-24258: SPIP v4
SPIP v4.1.5 and earlier was discovered to contain a SQL injection vulnerability via the _oups parameter. This vulnerability allows attackers to execute arbitrary code via a crafted POST request.
Ubuntu
SPIP vulnerabilities
vendor_ubuntu·2025-03-04·CVSS 6.2
CVE-2022-28959 [MEDIUM] SPIP vulnerabilities
Title: SPIP vulnerabilities
Summary: Several security issues were fixed in spip.
It was discovered that svg-sanitizer, vendored in SPIP, did not properly
sanitize SVG/XML content. An attacker could possibly use this issue to
perform cross site scripting. This issue only affected Ubuntu 24.10.
(CVE-2022-23638)
It was discovered that SPIP did not properly sanitize certain inputs. A
remote attacker could possibly use this issue to perform cross site
scripting. This issue only affected Ubuntu 18.04 LTS. (CVE-2022-28959)
It was discovered that SPIP did not properly sanitize certain inputs. A
remote attacker could possibly use this issue to perform PHP injection
attacks. This issue only affected Ubuntu 18.04 LTS. (CVE-2022-28960)
It was discovered that SPIP did not properly sanitize certain
Debian
CVE-2023-24258: spip - SPIP v4.1.5 and earlier was discovered to contain a SQL injection vulnerability ...
vendor_debian·2023·CVSS 9.8
CVE-2023-24258 [CRITICAL] CVE-2023-24258: spip - SPIP v4.1.5 and earlier was discovered to contain a SQL injection vulnerability ...
SPIP v4.1.5 and earlier was discovered to contain a SQL injection vulnerability via the _oups parameter. This vulnerability allows attackers to execute arbitrary code via a crafted POST request.
Scope: local
bullseye: resolved (fixed in 3.2.11-3+deb11u6)
forky: resolved (fixed in 4.1.7+dfsg-1)
sid: resolved (fixed in 4.1.7+dfsg-1)
trixie: resolved (fixed in 4.1.7+dfsg-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://blog.spip.net/Mise-a-jour-de-securite-sortie-de-SPIP-4-1-7-SPIP-4-0-9-et-SPIP-3-2-17.htmlhttps://github.com/Abyss-W4tcher/ab4yss-wr4iteups/blob/ffa980faa9e3598d49d6fb7def4f7a67cfb5f427/SPIP%20-%20Pentest/SPIP%204.1.5/SPIP_4.1.5_AND_BEFORE_AUTH_SQLi_Abyss_Watcher.mdhttps://www.debian.org/security/2023/dsa-5325https://blog.spip.net/Mise-a-jour-de-securite-sortie-de-SPIP-4-1-7-SPIP-4-0-9-et-SPIP-3-2-17.htmlhttps://github.com/Abyss-W4tcher/ab4yss-wr4iteups/blob/ffa980faa9e3598d49d6fb7def4f7a67cfb5f427/SPIP%20-%20Pentest/SPIP%204.1.5/SPIP_4.1.5_AND_BEFORE_AUTH_SQLi_Abyss_Watcher.mdhttps://www.debian.org/security/2023/dsa-5325
2023-02-27
Published