Vulnerabilities > CVE-2020-28984
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
prive/formulaires/configurer_preferences.php in SPIP before 3.2.8 does not properly validate the couleur, display, display_navigation, display_outils, imessage, and spip_ecran parameters.
Vulnerable Configurations
References
- https://git.spip.net/spip/spip/commit/ae4267eba1022dabc12831ddb021c5d6e09040f8
- https://git.spip.net/spip/spip/commit/ae4267eba1022dabc12831ddb021c5d6e09040f8
- https://git.spip.net/spip/spip/compare/v3.2.7...v3.2.8
- https://git.spip.net/spip/spip/compare/v3.2.7...v3.2.8
- https://lists.debian.org/debian-lts-announce/2020/12/msg00036.html
- https://lists.debian.org/debian-lts-announce/2020/12/msg00036.html
- https://www.debian.org/security/2020/dsa-4798
- https://www.debian.org/security/2020/dsa-4798