Source: spip
X-Debbugs-CC: [email protected]
Severity: important
Tags: security

Hi,

The following vulnerability was published for spip.

CVE-2024-53620[0]:
| A cross-site scripting (XSS) vulnerability in the Article module of
| SPIP v4.3.3 allows authenticated attackers to execute arbitrary web
| scripts or HTML via injecting a crafted payload into the Title
| parameter.

It's unclear whether this has been reported/fixed upstream, the
only refefence is:
https://grimthereaperteam.medium.com/ec1e8714c02e


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2024-53620
    https://www.cve.org/CVERecord?id=CVE-2024-53620

Please adjust the affected versions in the BTS as needed.

Reply via email to