← All CVEs

CVE-2023-27372

critical · 9.8

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1.

9.8
CVSS
99.7%
EPSS (exploit prob.)
100th
EPSS percentile
2023-02-28
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-502

Affected products

VendorProductAffected versions
spipspip< 3.2.18
spipspip>= 4.0.0, < 4.0.10
spipspip>= 4.1.0, < 4.1.8
spipspip4.2.0
spipspip4.2.0
spipspip4.2.0
debiandebian_linux11.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2023-27372