SPIP
cpe:2.3:a:spip:spip:*:*:*:*:*:*:*
- <= 4.1.0
- <= 4.2.0
- <= 4.3.0
A vulnerability in SPIP versions prior to 4.3.6, 4.2.17, and 4.1.20 allows unauthorized content disclosure in the private area. The issue arises because the application fails to properly validate authorization when displaying article and section content in AJAX-loaded fragments. This oversight enables an authenticated attacker to access restricted content. Notably, the SPIP security screen does not mitigate this vulnerability.
Exploitation of this vulnerability leads to unauthorized access to restricted content in the private area of the application.
Users are advised to update to SPIP versions 4.3.6, 4.2.17, or 4.1.20.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.