Source: spip
X-Debbugs-CC: [email protected]
Severity: important
Tags: security

Hi,

The following vulnerability was published for spip.

CVE-2024-53619[0]:
| An authenticated arbitrary file upload vulnerability in the
| Documents module of SPIP v4.3.3 allows attackers to execute
| arbitrary code via uploading a crafted PDF file.

It's unclear whether this has been reported/fixed upstream, the
only reference is:
https://grimthereaperteam.medium.com/spip-4-3-3-malicious-file-upload-xss-in-pdf-526c03bb1776

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2024-53619
    https://www.cve.org/CVERecord?id=CVE-2024-53619

Please adjust the affected versions in the BTS as needed.

Reply via email to