Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-09252
HistoryJan 28, 2022 - 12:00 a.m.

SPIP SVG Cross-Site Scripting Vulnerability

2022-01-2800:00:00
China National Vulnerability Database
www.cnvd.org.cn
8
spip
cross-site scripting
vulnerability
web application
client-side data
attack

EPSS

0.001

Percentile

25.8%

SPIP is a Web-based content publishing system. A cross-site scripting vulnerability exists in SPIP, which stems from the lack of proper validation of client-side data by the WEB application. An attacker could exploit the vulnerability to execute client-side code.