← Back to browse · API

CVE-2024-7954

Severity
CRITICAL
CVSS
9.8
EPSS
0.90053
Risk score
70.72
CISA KEV
No
PoC
No
Published
2024-08-23
Modified
2025-11-22
First seen
2026-08-07
Aliases
EUVD-2024-48791, GHSA-42MV-3H37-WFH9
Products
SPIP:SPIP 4.1.0 <4.1.16, SPIP:SPIP 4.2.0 <4.2.13, SPIP:SPIP 4.3.0-alpha <4.3.0-alpha2
Sources
euvd EUVD-2024-48791

Description

The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can execute arbitrary PHP as the SPIP user by sending a crafted HTTP request.

References