CVE-2019-16391

MEDIUM

SPIP <3.1.11, <3.2.5 - Privilege Escalation

Title source: llm
STIX 2.1

Description

SPIP before 3.1.11 and 3.2 before 3.2.5 allows authenticated visitors to modify any published content and execute other modifications in the database. This is related to ecrire/inc/meta.php and ecrire/inc/securiser_action.php.

References (8)

Core 8
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_bugtraq
https://seclists.org/bugtraq/2019/Sep/40
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2019/dsa-4532
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2019/10/msg00038.html
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/4536-1/

Scores

CVSS v3 6.5
EPSS 0.0087
EPSS Percentile 75.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Details

Status published
Products (5)
canonical/ubuntu_linux 18.04
debian/debian_linux 8.0
debian/debian_linux 9.0
debian/debian_linux 10.0
spip/spip < 3.1.11
Published Sep 17, 2019
Tracked Since Feb 18, 2026