VulnerabilityDeferred
CVE-2024-7954
The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability.
CRITICAL 9.8EPSS 90.1%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 90.1%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can execute arbitrary PHP as the SPIP user by sending a crafted HTTP request.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 90.05% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-95, CWE-1286
- Source
- disclosure@vulncheck.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.