CVE-2021-44120

Description

SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability in ecrire/public/interfaces.php, adding the function safehtml to the vulnerable fields. An editor is able to modify his personal information. If the editor has an article written and available, when a user goes to the public site and wants to read the authors information, the malicious code will be executed. The Who are you and Website Name fields are vulnerable.

Risk Information

Base Score
5.4
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.366

Associated Vulnerability

VulnerabilityOS Platform
website engine for publishing (USN-5482-1) spip_3.1.4-4~deb9u5build0.18.04.1_all.debLinux
website engine for publishing (USN-5482-1) spip_3.2.11-3+deb11u3build0.21.10.1_all.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234