CRITICAL🇵🇱 Wersja polska

CVE-2024-7954

CVSS 9.8v3.1pub. 2024-08-23upd. 2026-04-15

The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can execute arbitrary PHP as the SPIP user by sending a crafted HTTP request.

🤖 AI Analysis
How it works

The vulnerability is classified as CWE-95 (improper neutralization of directives in dynamically evaluated code) and CWE-1286, indicating improper handling of user input in the porte_plume plugin. A remote, unauthenticated attacker can submit a crafted HTTP request, which results in the execution of arbitrary PHP code in the context of the SPIP user. The attack requires no authorization or user interaction, making it particularly dangerous.

Impact

An attacker can execute arbitrary PHP code on the server with SPIP process privileges, leading to complete takeover of the application, data leakage, content modification, and further movement in the infrastructure (lateral movement).

Mitigation & patch

SPIP must be urgently updated to version 4.30-alpha2, 4.2.13, or 4.1.16 (depending on the branch used). Details are available in the official vendor notice: https://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-3-0-alpha2-SPIP-4-2-13-SPIP-4.html

Who is affected

SPIP in versions before 4.30-alpha2, before 4.2.13, and before 4.1.16 — all installations using the porte_plume plugin

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEAuth Bypass
CWE
References