
π Vulnerability Details
- CVE: Pending assignment (tracked as VE-2024-7954)
- Attack Vector: Unauthenticated HTTP request exploitation
- Affected Versions:
- SPIP 4.2.0 β 4.2.5
- Porte Plume β€ 3.4.1
π¬ Technical Analysis
The vulnerability allows arbitrary PHP execution via:
POST /spip.php?page=porte_plume&action=upload
With crafted name
parameter containing malicious code.
π οΈ Mitigation Steps:
- Emergency Workaround:
rm -rf plugins/porte_plume/
- Official Patch:
composer require spip/spip:^4.2.6
- Forensics:
grep -r "porte_plume.*action=upload" /var/log/apache2/
Download Free Here!
π References:
SPIP Git Commit Fix
OWASP RCE Prevention
#CMSecurity #VulnerabilityManagement #DevSecOps