Lucene search

K
cvelistMitreCVELIST:CVE-2023-52322
HistoryJan 04, 2024 - 12:00 a.m.

CVE-2023-52322

2024-01-0400:00:00
mitre
www.cve.org
3
spip
xss
vulnerability
ecrire/public/assembler.php
input restriction

EPSS

0.001

Percentile

20.6%

ecrire/public/assembler.php in SPIP before 4.1.13 and 4.2.x before 4.2.7 allows XSS because input from _request() is not restricted to safe characters such as alphanumerics.

EPSS

0.001

Percentile

20.6%