Lucene search

K
cvelistMitreCVELIST:CVE-2023-24258
HistoryFeb 27, 2023 - 12:00 a.m.

CVE-2023-24258

2023-02-2700:00:00
mitre
www.cve.org
2
spip
sql injection
vulnerability
post request
arbitrary code

0.002 Low

EPSS

Percentile

55.1%

SPIP v4.1.5 and earlier was discovered to contain a SQL injection vulnerability via the _oups parameter. This vulnerability allows attackers to execute arbitrary code via a crafted POST request.

0.002 Low

EPSS

Percentile

55.1%