CVE-2023-27372
CVE-2023-27372
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Produtos afetados
n/a · n/aPoCs públicas encontradas — 18
githubgithub.com/nuts7/CVE-2023-27372★ 68githubgithub.com/Chocapikk/CVE-2023-27372★ 8githubgithub.com/0SPwn/CVE-2023-27372-PoC★ 6githubgithub.com/Ap0dexMe0/CVE-2023-27372★ 3githubgithub.com/izzz0/CVE-2023-27372-POC★ 2githubgithub.com/1Ronkkeli/spip-cve-2023-27372-rce★ 2githubgithub.com/1amthebest1/CVE-2023-27372★ 0githubgithub.com/dream434/CVE-2023-27372★ 0githubgithub.com/KirolosKhairy/CVE-2023-27372★ 0githubgithub.com/estebanzarate/CVE-2023-27372-SPIP-4.2.1-Unauthenticated-RCE-PoC★ 0githubgithub.com/scriniariii/CVE-2023-27372★ 0githubgithub.com/G01d3nW01f/cve-2023-27372★ 0githubgithub.com/redboltsec/CVE-2023-27372-PoC★ 0exploitdbwww.exploit-db.com/exploits/51536não verificadocve_referencepacketstormsecurity.com/files/173044/SPIP-4.2.1-Remote-Code-Execution.htmlnão verificadocve_referencepacketstorm.news/files/id/171921não verificadocve_referencepacketstorm.news/files/id/173044não verificadocve_referencepacketstormsecurity.com/files/171921/SPIP-Remote-Command-Execution.htmlnão verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://packetstormsecurity.com/files/171921/SPIP-Remote-Command-Execution.htmlhttp://packetstormsecurity.com/files/173044/SPIP-4.2.1-Remote-Code-Execution.htmlhttps://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-2-1-SPIP-4-1-8-SPIP-4-0-10-et.htmlhttps://git.spip.net/spip/spip/commit/5aedf49b89415a4df3eb775eee3801a2b4b88266https://git.spip.net/spip/spip/commit/96fbeb38711c6706e62457f2b732a652a04a409dhttps://packetstorm.news/files/id/171921https://packetstorm.news/files/id/173044https://www.debian.org/security/2023/dsa-5367