CVE-2024-23659Cross-site Scripting in Spip

Severity
6.1MEDIUMNVD
EPSS
0.9%
top 24.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 19

Description

SPIP before 4.1.14 and 4.2.x before 4.2.8 allows XSS via the name of an uploaded file. This is related to javascript/bigup.js and javascript/bigup.utils.js.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages3 packages

NVDspip/spip4.2.04.2.8+1
debiandebian/spip< spip 4.1.15+dfsg-1 (forky)
Debianspip/spip< 4.1.15+dfsg-1+1

Patches

🔴Vulnerability Details

2
OSV
CVE-2024-23659: SPIP before 42024-01-19
GHSA
GHSA-7x4m-7295-wr3j: SPIP before 42024-01-19

📋Vendor Advisories

1
Debian
CVE-2024-23659: spip - SPIP before 4.1.14 and 4.2.x before 4.2.8 allows XSS via the name of an uploaded...2024
CVE-2024-23659 — Cross-site Scripting in Spip | cvebase