vendor:
SPIP
by:
Nicolas CHATELAIN, Sysdream
8,8
CVSS
HIGH
Cross-Site Request Forgery
352
CWE
Product Name: SPIP
Affected Version From: Version <= 3.1.2
Affected Version To: Version <= 3.1.2
Patch Exists: YES
Related CWE: CVE-2016-7980
CPE: SPIP
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2016
SPIP 3.1.2 Exec Code Cross-Site Request Forgery (CVE-2016-7980)
The vulnerable request to `valider_xml` (see: *SPIP 3.1.2 Template Compiler/Composer PHP Code Execution - CVE-2016-7998*) is vulnerable to Cross-Site Request Forgery, allowing the execution of the CVE-2016-7998 attack by tricking an administrator to open the malicious link.
Mitigation:
Fixes issued for CSRF