CVE-2019-11071

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
10/04/2019
Last modified:
28/09/2020

Description

SPIP 3.1 before 3.1.10 and 3.2 before 3.2.4 allows authenticated visitors to execute arbitrary code on the host server because var_memotri is mishandled.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:* 3.1.0 (including) 3.1.10 (excluding)
cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:* 3.2.0 (including) 3.2.4 (excluding)
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*