GHSA-px65-33x4-mwqqCriticalCVSS 9.8

SPIP before 4.4.18 contains a missing authorization vulnerability in the administrative action...

Published
September 11, 2026
Last Modified
September 11, 2026

🔗 CVE IDs covered (1)

📋 Description

SPIP before 4.4.18 contains a missing authorization vulnerability in the administrative action endpoints under ecrire/action/ that allows unauthenticated attackers to perform privileged actions by supplying a valid HMAC-SHA256 nonce without any server-side permission check via autoriser(). Attackers can obtain a valid nonce, compute it for any action as the anonymous user, and invoke the editer_auteur action directly over HTTP to reset the password of any user account, including the administrator.

🔗 References (5)