CVE-2024-7954

CVSS V2 None CVSS V3 None
Description
The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can execute arbitrary PHP as the SPIP user by sending a crafted HTTP request.
Overview
  • CVE ID
  • CVE-2024-7954
  • Assigner
  • VulnCheck
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-08-23T17:43:20.967Z
  • Last Modified Date
  • 2024-08-23T18:31:44.888Z
History
Created Old Value New Value Data Type Notes
2024-08-24 13:04:53 Added to TrackCVE