CVE-2021-44118
26.01.2022, 12:15
SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability. To exploit the vulnerability, a visitor must browse to a malicious SVG file. The vulnerability allows an authenticated attacker to inject malicious code running on the client side into web pages visited by other users (stored XSS).
Vendor | Product | Version |
---|---|---|
spip | spip | 4.0.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References