Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-44122

Опубликовано: 26 янв. 2022
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.8
CVSS3: 8.8

Описание

SPIP 4.0.0 is affected by a Cross Site Request Forgery (CSRF) vulnerability in ecrire/public/aiguiller.php, ecrire/public/balises.php, ecrire/balise/formulaire_.php. To exploit the vulnerability, a visitor must visit a malicious website which redirects to the SPIP website. It is also possible to combine XSS vulnerabilities in SPIP 4.0.0 to exploit it. The vulnerability allows an authenticated attacker to execute malicious code without the knowledge of the user on the website (CSRF).

РелизСтатусПримечание
bionic

released

3.1.4-4~deb9u5build0.18.04.1
devel

not-affected

4.0.1
esm-apps/bionic

released

3.1.4-4~deb9u5build0.18.04.1
esm-apps/focal

released

3.2.7-1ubuntu0.1
esm-apps/jammy

not-affected

4.0.1
esm-apps/noble

not-affected

4.0.1
esm-apps/xenial

needed

focal

released

3.2.7-1ubuntu0.1
impish

released

3.2.11-3+deb11u3build0.21.10.1
jammy

not-affected

4.0.1

Показывать по

EPSS

Процентиль: 60%
0.00392
Низкий

6.8 Medium

CVSS2

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
около 4 лет назад

SPIP 4.0.0 is affected by a Cross Site Request Forgery (CSRF) vulnerability in ecrire/public/aiguiller.php, ecrire/public/balises.php, ecrire/balise/formulaire_.php. To exploit the vulnerability, a visitor must visit a malicious website which redirects to the SPIP website. It is also possible to combine XSS vulnerabilities in SPIP 4.0.0 to exploit it. The vulnerability allows an authenticated attacker to execute malicious code without the knowledge of the user on the website (CSRF).

CVSS3: 8.8
debian
около 4 лет назад

SPIP 4.0.0 is affected by a Cross Site Request Forgery (CSRF) vulnerab ...

github
около 4 лет назад

SPIP 4.0.0 is affected by a Cross Site Request Forgery (CSRF) vulnerability in ecrire/public/aiguiller.php, ecrire/public/balises.php, ecrire/balise/formulaire_.php. To exploit the vulnerability, a visitor must visit a malicious website which redirects to the SPIP website. It is also possible to combine XSS vulnerabilities in SPIP 4.0.0 to exploit it. The vulnerability allows an authenticated attacker to execute malicious code without the knowledge of the user on the website (CSRF).

EPSS

Процентиль: 60%
0.00392
Низкий

6.8 Medium

CVSS2

8.8 High

CVSS3