VulnerabilityModified
CVE-2019-16391
SPIP before 3.1.11 and 3.2 before 3.2.5 allows authenticated visitors to modify any published content and execute other modifications in the database.
MEDIUM 6.5EPSS 1.49%
Does this matter?
Lower severity and a low EPSS score (1.49%). Track it; it rarely justifies an emergency change on its own.
Description
SPIP before 3.1.11 and 3.2 before 3.2.5 allows authenticated visitors to modify any published content and execute other modifications in the database. This is related to ecrire/inc/meta.php and ecrire/inc/securiser_action.php.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 1.49% probability · 73th percentile
- CISA KEV
- Not listed
- Affected
- spip/spip · canonical/ubuntu linux · debian/debian linux
- Source
- cve@mitre.org
References
- https://blog.spip.net/Mise-a-jour-CRITIQUE-de-securite-Sortie-de-SPIP-3-2-5-et-SPIP-3-1-11.htmlPatch, Vendor Advisory
- https://blog.spip.net/Mise-a-jour-CRITIQUE-de-securite-Sortie-de-SPIP-3-2-5-et-SPIP-3-1-11.html?lang=frPatch, Vendor Advisory
- https://git.spip.net/SPIP/spip/commit/187952ce85e73b52c2753f2d54fc2c44807b8f79Patch, Vendor Advisory
- https://git.spip.net/SPIP/spip/commit/3cbc758400323ab006c00ea78eacdb8f76aa5f66Patch, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2019/10/msg00038.htmlMailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Sep/40Mailing List, Third Party Advisory
- https://usn.ubuntu.com/4536-1/Third Party Advisory
- https://www.debian.org/security/2019/dsa-4532Third Party Advisory
- https://blog.spip.net/Mise-a-jour-CRITIQUE-de-securite-Sortie-de-SPIP-3-2-5-et-SPIP-3-1-11.htmlPatch, Vendor Advisory
- https://blog.spip.net/Mise-a-jour-CRITIQUE-de-securite-Sortie-de-SPIP-3-2-5-et-SPIP-3-1-11.html?lang=frPatch, Vendor Advisory
- https://git.spip.net/SPIP/spip/commit/187952ce85e73b52c2753f2d54fc2c44807b8f79Patch, Vendor Advisory
- https://git.spip.net/SPIP/spip/commit/3cbc758400323ab006c00ea78eacdb8f76aa5f66Patch, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2019/10/msg00038.htmlMailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Sep/40Mailing List, Third Party Advisory
- https://usn.ubuntu.com/4536-1/Third Party Advisory
- https://www.debian.org/security/2019/dsa-4532Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.