SPIP before 4.2.1 allows Remote Code Execution via form...
Critical severity
Unreviewed
Published
Feb 28, 2023
to the GitHub Advisory Database
•
Updated Jun 29, 2023
Description
Published by the National Vulnerability Database
Feb 28, 2023
Published to the GitHub Advisory Database
Feb 28, 2023
Last updated
Jun 29, 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1.
References