CVE-2024-8517: Spip
Critical severity, CVSS 9.8. EPSS: 94.6% chance of exploitation in the next 30 days.
SPIP before 4.3.2, 4.2.16, and 4.1.18 is vulnerable to a command injection issue. A remote and unauthenticated attacker can execute arbitrary operating system commands by sending a crafted multipart file upload HTTP request.
Affected products
- Spip Spip: from 4.0.0, before 4.1.18 (fixed in 4.1.18); from 4.2.0, up to and including 4.2.15; version 4.3.0 only; version 4.3.1 only
Published 2024-09-06. Last modified 2026-06-17.