← Back to browse · API

CVE-2022-37155

Severity
HIGH
CVSS
8.8
EPSS
0.39966
Risk score
49.19
CISA KEV
No
PoC
No
Published
2022-12-13
Modified
2025-04-22
First seen
2026-08-07
Aliases
EUVD-2022-39808, GHSA-7C7W-25XJ-4MP8
Products
n/a:n/a n/a
Sources
euvd EUVD-2022-39808

Description

RCE in SPIP 3.1.13 through 4.1.2 allows remote authenticated users to execute arbitrary code via the _oups parameter.

References