Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39758
HistoryMar 13, 2023 - 5:57 a.m.

Remote Code Execution (RCE)

2023-03-1305:57:35
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
29
spip
remote code execution
form values
attacker
malicious code

EPSS

0.974

Percentile

99.9%

SPIP is vulnerable to Remote Code Execution (RCE). The vulnerability exists because of the improper sanitization of form values in the public area, allowing an attacker to inject and execute malicious code.