The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can execute arbitrary PHP as the SPIP user by sending a crafted HTTP request.
The vulnerability is classified as CWE-95 (improper neutralization of directives in dynamically evaluated code) and CWE-1286, indicating improper handling of user input in the porte_plume plugin. A remote, unauthenticated attacker can submit a crafted HTTP request, which results in the execution of arbitrary PHP code in the context of the SPIP user. The attack requires no authorization or user interaction, making it particularly dangerous.
An attacker can execute arbitrary PHP code on the server with SPIP process privileges, leading to complete takeover of the application, data leakage, content modification, and further movement in the infrastructure (lateral movement).
SPIP must be urgently updated to version 4.30-alpha2, 4.2.13, or 4.1.16 (depending on the branch used). Details are available in the official vendor notice: https://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-3-0-alpha2-SPIP-4-2-13-SPIP-4.html
SPIP in versions before 4.30-alpha2, before 4.2.13, and before 4.1.16 — all installations using the porte_plume plugin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H