CVE-2023-27372
28.02.2023, 20:15
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1.Enginsight
Vendor | Product | Version |
---|---|---|
spip | spip | 𝑥 < 3.2.18 |
spip | spip | 4.0.0 ≤ 𝑥 < 4.0.10 |
spip | spip | 4.1.0 ≤ 𝑥 < 4.1.8 |
spip | spip | 4.2.0 |
spip | spip | 4.2.0:alpha |
spip | spip | 4.2.0:alpha2 |
debian | debian_linux | 11.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References