SPIP v4.1.5 and earlier was discovered to contain a SQL...
Critical severity
Unreviewed
Published
Feb 27, 2023
to the GitHub Advisory Database
•
Updated Mar 25, 2023
Description
Published by the National Vulnerability Database
Feb 27, 2023
Published to the GitHub Advisory Database
Feb 27, 2023
Last updated
Mar 25, 2023
SPIP v4.1.5 and earlier was discovered to contain a SQL injection vulnerability via the _oups parameter. This vulnerability allows attackers to execute arbitrary code via a crafted POST request.
References