Improper access control in SPIP - CVE-2019-16391
Published: September 29, 2019
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions related to ecrire/inc/meta.php and ecrire/inc/securiser_action.php scripts. A remote authenticated website visitor can bypass implemented security restrictions and modify any published content and execute other modifications in the database
Affected software
spip (Debian package)
spip (Ubuntu package)
Ubuntu
How to mitigate CVE-2019-16391
spip (Debian package) - addressed in versions 3.1.4-4~deb9u3, 3.2.4-1+deb10u1
spip (Ubuntu package) - update to 3.1.4-4~deb9u3build0.18.04.1
External References
- https://blog.spip.net/Mise-a-jour-CRITIQUE-de-securite-Sortie-de-SPIP-3-2-5-et-SPIP-3-1-11.html
- https://blog.spip.net/Mise-a-jour-CRITIQUE-de-securite-Sortie-de-SPIP-3-2-5-et-SPIP-3-1-11.html?lang=fr
- https://git.spip.net/SPIP/spip/commit/187952ce85e73b52c2753f2d54fc2c44807b8f79
- https://git.spip.net/SPIP/spip/commit/3cbc758400323ab006c00ea78eacdb8f76aa5f66
- https://seclists.org/bugtraq/2019/Sep/40