← Back to browse · API

CVE-2024-8517

Severity
CRITICAL
CVSS
9.8
EPSS
0.94614
Risk score
72.31
CISA KEV
No
PoC
No
Published
2024-09-06
Modified
2025-11-22
First seen
2026-08-07
Aliases
EUVD-2024-49235, GHSA-7W4R-XXR6-XRCJ
Products
SPIP:SPIP 4.1.0 ≤4.1.18, SPIP:SPIP 4.2.0 ≤4.2.15, SPIP:SPIP 4.3.0 ≤4.3.1
Sources
euvd EUVD-2024-49235

Description

SPIP before 4.3.2, 4.2.16, and 4.1.18 is vulnerable to a command injection issue. A remote and unauthenticated attacker can execute arbitrary operating system commands by sending a crafted multipart file upload HTTP request.

References