CVE-2024-8517

CVSS V2 None CVSS V3 None
Description
SPIP before 4.3.2, 4.2.16, and 4.1.18 is vulnerable to a command injection issue. A remote and unauthenticated attacker can execute arbitrary operating system commands by sending a crafted multipart file upload HTTP request.
Overview
  • CVE ID
  • CVE-2024-8517
  • Assigner
  • VulnCheck
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-09-06T15:55:35.349Z
  • Last Modified Date
  • 2024-09-06T20:30:45.388Z
History
Created Old Value New Value Data Type Notes
2024-09-07 13:04:19 Added to TrackCVE