CVE-2025-71242Improper Authorization in Spip

Severity
5.3MEDIUMNVD
EPSS
0.0%
top 90.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 19

Description

SPIP before 4.3.6, 4.2.17, and 4.1.20 allows unauthorized content disclosure in the private area. The application does not properly check authorization when displaying content of articles and sections (rubriques) in AJAX-loaded fragments, allowing an authenticated attacker to access restricted content. This vulnerability is not mitigated by the SPIP security screen.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Packages3 packages

NVDspip/spip4.1.04.1.20+2
debiandebian/spip< spip 4.3.6+dfsg-1 (forky)
Debianspip/spip< 4.3.6+dfsg-1+1

🔴Vulnerability Details

2
OSV
CVE-2025-71242: SPIP before 42026-02-19
GHSA
GHSA-cgwr-5223-r4pg: SPIP before 42026-02-19

📋Vendor Advisories

1
Debian
CVE-2025-71242: spip - SPIP before 4.3.6, 4.2.17, and 4.1.20 allows unauthorized content disclosure in ...2025

🕵️Threat Intelligence

1
Wiz
CVE-2025-71242 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2025-71242 — Improper Authorization in Spip | cvebase