CVE-2023-52322
published 2024-01-04CVE-2023-52322: ecrire/public/assembler.php in SPIP before 4.1.13 and 4.2.x before 4.2.7 allows XSS because input from _request() is not restricted to safe characters such as…
PriorityP426medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.44%
35.8th percentile
ecrire/public/assembler.php in SPIP before 4.1.13 and 4.2.x before 4.2.7 allows XSS because input from _request() is not restricted to safe characters such as alphanumerics.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | spip | < spip 3.2.11-3+deb11u10 (bullseye) | spip 3.2.11-3+deb11u10 (bullseye) |
| spip | spip | < 4.1.13 | 4.1.13 |
| spip | spip | >= 0 < 3.2.11-3+deb11u10 | 3.2.11-3+deb11u10 |
| spip | spip | >= 0 < 4.1.13+dfsg-1 | 4.1.13+dfsg-1 |
| spip | spip | >= 0 < 4.1.13+dfsg-1 | 4.1.13+dfsg-1 |
| spip | spip | >= 4.2.0 < 4.2.7 | 4.2.7 |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
osv6.1MEDIUM
vendor_debian6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-52322: ecrire/public/assembler
osv·2024-01-04·CVSS 6.1
CVE-2023-52322 [MEDIUM] CVE-2023-52322: ecrire/public/assembler
ecrire/public/assembler.php in SPIP before 4.1.13 and 4.2.x before 4.2.7 allows XSS because input from _request() is not restricted to safe characters such as alphanumerics.
GHSA
GHSA-p88h-866g-7w72: ecrire/public/assembler
ghsa_unreviewed·2024-01-04
CVE-2023-52322 [MEDIUM] CWE-79 GHSA-p88h-866g-7w72: ecrire/public/assembler
ecrire/public/assembler.php in SPIP before 4.1.3 and 4.2.x before 4.2.7 allows XSS because input from _request() is not restricted to safe characters such as alphanumerics.
Debian
CVE-2023-52322: spip - ecrire/public/assembler.php in SPIP before 4.1.13 and 4.2.x before 4.2.7 allows ...
vendor_debian·2023·CVSS 6.1
CVE-2023-52322 [MEDIUM] CVE-2023-52322: spip - ecrire/public/assembler.php in SPIP before 4.1.13 and 4.2.x before 4.2.7 allows ...
ecrire/public/assembler.php in SPIP before 4.1.13 and 4.2.x before 4.2.7 allows XSS because input from _request() is not restricted to safe characters such as alphanumerics.
Scope: local
bullseye: resolved (fixed in 3.2.11-3+deb11u10)
forky: resolved (fixed in 4.1.13+dfsg-1)
sid: resolved (fixed in 4.1.13+dfsg-1)
trixie: resolved (fixed in 4.1.13+dfsg-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://blog.spip.net/Mise-a-jour-de-maintenance-et-securite-sortie-de-SPIP-4-2-7-SPIP-4-1-13.html?lang=frhttps://git.spip.net/spip/spip/commit/e90f5344b8c82711053053e778d38a35e42b7bcbhttps://lists.debian.org/debian-lts-announce/2024/03/msg00014.htmlhttps://blog.spip.net/Mise-a-jour-de-maintenance-et-securite-sortie-de-SPIP-4-2-7-SPIP-4-1-13.html?lang=frhttps://git.spip.net/spip/spip/commit/e90f5344b8c82711053053e778d38a35e42b7bcbhttps://lists.debian.org/debian-lts-announce/2024/03/msg00014.html
2024-01-04
Published