Improper access control in SPIP - #VU61219
Published: March 9, 2022
Vulnerability identifier: #VU61219
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote attacker can bypass implemented security restrictions and gain unauthorized access to the editorial object information.
Affected software
SPIP
spip (Debian package)
spip (Debian package)
Remediation
Install updates from vendor's website.
SPIP - addressed in versions 3.2.14, 4.0.5
spip (Debian package) - addressed in versions 3.2.4-1+deb10u7, 3.2.11-3+deb11u3
spip (Debian package) - addressed in versions 3.2.4-1+deb10u7, 3.2.11-3+deb11u3