SPIP
cpe:2.3:a:spip:spip:*:*:*:*:*:*:*
- <= 4.4.0
A cross-site scripting (XSS) vulnerability has been identified in SPIP versions prior to 4.4.8. This issue arises in the public area under certain edge-case usage patterns, where the 'echapper_html_suspect()' function fails to properly detect all forms of malicious content. As a result, an attacker can inject scripts that execute in the browser of a visitor. Notably, this vulnerability is not addressed by SPIP's security screen.
Exploitation of this vulnerability allows for cross-site scripting, where injected scripts are executed in the context of the user's browser.
Users can update to SPIP version 4.4.8, which includes a fix for this vulnerability. Instructions for updating are available on the SPIP website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.