Vulnerabilities > CVE-2019-19830
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
NONE Integrity impact
HIGH Availability impact
NONE Summary
_core_/plugins/medias in SPIP 3.2.x before 3.2.7 allows remote authenticated authors to inject content into the database.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 11 | |
OS | 2 | |
OS | 1 |
Nessus
NASL family | Debian Local Security Checks |
NASL id | DEBIAN_DSA-4583.NASL |
description | A vulnerability was discovered in the SPIP publishing system, which could result in unauthorised writes to the database by authors. The oldstable distribution (stretch) is not affected. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 132062 |
published | 2019-12-16 |
reporter | This script is Copyright (C) 2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/132062 |
title | Debian DSA-4583-1 : spip - security update |
code |
|
References
- https://blog.spip.net/Mise-a-jour-CRITIQUE-de-securite-sortie-de-SPIP-3-2-7-SPIP-3-1-12.html
- https://blog.spip.net/Mise-a-jour-CRITIQUE-de-securite-sortie-de-SPIP-3-2-7-SPIP-3-1-12.html
- https://git.spip.net/SPIP/spip/commit/8eb11ba132b92696eb34d606d71aa8edf40e0f69
- https://git.spip.net/SPIP/spip/commit/8eb11ba132b92696eb34d606d71aa8edf40e0f69
- https://usn.ubuntu.com/4536-1/
- https://usn.ubuntu.com/4536-1/
- https://www.debian.org/security/2019/dsa-4583
- https://www.debian.org/security/2019/dsa-4583
- https://zone.spip.net/trac/spip-zone/changeset/118898/spip-zone/_core_/plugins/medias
- https://zone.spip.net/trac/spip-zone/changeset/118898/spip-zone/_core_/plugins/medias