← back
CVE-2023-27372criticalobserved exploitationCWE-502

CVE-2023-27372

100Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actcvss 9.8epss 100%
from disclosure to weapon111 days
Published on NVDFeb 28
1st PoC+111d
metasploitFeb 27
VulnCheck+64d
exploitation probability
100%top 1% of all CVEs
observed exploitation
yesVulnCheck
31 public exploit(s)
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a
public PoCs found31 VexDay Proof
exploitdbVexDay Proofwww.exploit-db.com/exploits/51536githubgithub.com/nuts7/CVE-2023-2737269githubgithub.com/Chocapikk/CVE-2023-273728githubgithub.com/0SPwn/CVE-2023-27372-PoC6githubgithub.com/Ap0dexMe0/CVE-2023-273723githubgithub.com/1Ronkkeli/spip-cve-2023-27372-rce2githubgithub.com/izzz0/CVE-2023-27372-POC2githubgithub.com/estebanzarate/CVE-2023-27372-SPIP-4.2.1-Unauthenticated-RCE-PoC1githubgithub.com/redboltsec/CVE-2023-27372-PoC0githubgithub.com/G01d3nW01f/cve-2023-273720githubgithub.com/1amthebest1/CVE-2023-273720githubgithub.com/scriniariii/CVE-2023-273720githubgithub.com/dream434/CVE-2023-273720githubgithub.com/KirolosKhairy/CVE-2023-273720vulncheckvulncheck.com/xdb/5a4ed18cbe25unverifiedcve_referencepacketstormsecurity.com/files/171921/SPIP-Remote-Command-Execution.htmlunverifiedcve_referencepacketstormsecurity.com/files/173044/SPIP-4.2.1-Remote-Code-Execution.htmlunverifiedvulncheckvulncheck.com/xdb/ab5928501616unverifiedcve_referencepacketstorm.news/files/id/173044unverifiedvulncheckvulncheck.com/xdb/a7444b0210e4unverifiedcve_referencepacketstorm.news/files/id/171921unverifiedvulncheckvulncheck.com/xdb/268a1b1d077aunverifiedvulncheckvulncheck.com/xdb/04607676aadbunverifiedvulncheckvulncheck.com/xdb/3ce4547b4b42unverifiedvulncheckvulncheck.com/xdb/81284a3b5750unverifiedvulncheckvulncheck.com/xdb/2f302d530f10unverifiedvulncheckvulncheck.com/xdb/32c0ec161ef4unverifiedvulncheckvulncheck.com/xdb/70071bb09a8bunverifiedvulncheckvulncheck.com/xdb/e1f2d4ed2e6bunverifiedvulncheckvulncheck.com/xdb/7fb69b769d96unverifiedvulncheckvulncheck.com/xdb/b8a19b503bfcunverified
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.