CVE-2024-23659
MEDIUMSPIP < 4.1.14 and 4.2.x < 4.2.8 - Cross-Site Scripting via Uploaded File Name
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-23659. PoCs published by amis13.
AI-analyzed exploit summary This repository contains a functional Python exploit for an unauthenticated Remote Code Execution (RCE) vulnerability in SPIP's BigUp plugin. The exploit leverages a multipart form submission to inject PHP payloads and execute arbitrary commands, returning output via HTTP headers.
Description
SPIP before 4.1.14 and 4.2.x before 4.2.8 allows XSS via the name of an uploaded file. This is related to javascript/bigup.js and javascript/bigup.utils.js.
Exploits (1)
This repository contains a functional Python exploit for an unauthenticated Remote Code Execution (RCE) vulnerability in SPIP's BigUp plugin. The exploit leverages a multipart form submission to inject PHP payloads and execute arbitrary commands, returning output via HTTP headers.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N