CVE-2021-44118
Description
SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability. To exploit the vulnerability, a visitor must browse to a malicious SVG file. The vulnerability allows an authenticated attacker to inject malicious code running on the client side into web pages visited by other users (stored XSS).
Risk Information
Base Score
5.4
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.104
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| website engine for publishing (USN-5482-1) spip_3.1.4-4~deb9u5build0.18.04.1_all.deb | Linux |
| website engine for publishing (USN-5482-1) spip_3.2.11-3+deb11u3build0.21.10.1_all.deb | Linux |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234