SPIP 在 4.4.18 之前版本中存在一个远程代码执行(RCE)漏洞。该漏洞位于 操作中: 参数在解析 SQL 表名时,未强制使用可编辑列的白名单机制,这使得持有有效 nonce 的攻击者能够向 表中注入攻击者控制的行数据。 攻击者可通过提供 以及经过构造的 和 值来利用此漏洞。这些值在 cron 任务队列被处理(drained)时会被反序列化并执行,从而在底层系统上实现任意 PHP 函数执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-72709 | 9.8 CRITICAL | SPIP < 4.4.18 Missing Authorization via ecrire/action/ editer_auteur |
| CVE-2026-72708 | 7.5 HIGH | SPIP < 4.4.18 Unauthenticated SQL Injection via sitemap annee Parameter |
No comments yet