vendor:
SPIP
by:
N/A
8,8
CVSS
HIGH
PHP Code Execution
94
CWE
Product Name: SPIP
Affected Version From: 3.1.2
Affected Version To: 3.1.2
Patch Exists: YES
Related CWE: CVE-2016-7998
CPE: N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2016
SPIP 3.1.2 Template Compiler/Composer PHP Code Execution (CVE-2016-7998)
The SPIP template composer/compiler does not correctly handle SPIP 'INCLUDE/INCLURE' Tags, allowing PHP code execution by an authenticated user. This vulnerability can be exploited using the CSRF or the XSS vulnerability also found in this advisory.
Mitigation:
The vulnerability has been fixed in SPIP 3.1.3.