TROYANOSYVIRUS
Voltar para CVEs

CVE-2016-7980

N/A

Descricao

Cross-site request forgery (CSRF) vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to hijack the authentication of administrators for requests that execute the XML validator on a local file via a crafted valider_xml request. NOTE: this issue can be combined with CVE-2016-7998 to execute arbitrary PHP code.

Detalhes CVE

Pontuacao CVSS v3.1N/A
Publicado1/18/2017
Ultima modificacao4/20/2025
Fontenvd
Avistamentos honeypot0

Produtos afetados

spip:spip

Fraquezas (CWE)

CWE-352

Correlacoes IOC

Sem correlacoes registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.