Description
SPIP before 4.2.15 allows Cross-Site Scripting (XSS) via crafted content in HTML code tags. The application does not properly verify JavaScript within code tags, allowing an attacker to inject malicious scripts that execute in a victim's browser.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
4.2.0 (semver) before 4.2.15
Credits
JO
References
blog.spip.net/...ance-et-securite-sortie-de-SPIP-4-2-15.html
git.spip.net/spip/spip
www.vulncheck.com/...spip-cross-site-scripting-via-code-tags (VulnCheck Advisory: SPIP < 4.2.15 Cross-Site Scripting via Code Tags)