Deserialization of Untrusted Data in SPIP - CVE-2023-27372
Published: March 3, 2023 / Updated: May 9, 2025
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insecure input validation when processing serialized data. A remote attacker can pass specially crafted data to the application and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Debian Linux
spip (Debian package)
How to mitigate CVE-2023-27372
spip (Debian package) - update to 3.2.11-3+deb11u7
Links to Public Exploits and PoC-codes
- Exploit #11361 - spip-cve-2023-27372-rce (SPIP CVE-2023-27372 Unauthenticated RCE Exploit (Web Shell Upload)) (May 9, 2025)
- Exploit #10675 - SPIP v4.2.0 - Remote Code Execution (Unauthenticated) (October 25, 2024)
- Exploit #10504 - SPIP form PHP Injection (September 11, 2024)
- Exploit #10384 - CVE-2023-27372 (Perform With Mass Remote Code Execution In SPIP Version (4.2.1)) (August 16, 2024)
- Exploit #10191 - CVE-2023-27372-PoC (This is a PoC for CVE-2023-27372 which spawns a fully interactive shell. ) (July 5, 2024)
- Exploit #9140 - CVE-2023-27372 (SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1.) (June 26, 2023)
- Exploit #8991 - SPIP form PHP Injection (April 17, 2023)