Description
SPIP versions prior to 4.4.10 contain a SQL injection vulnerability that allows authenticated low-privilege users to execute arbitrary SQL queries by manipulating union-based injection techniques. Attackers can exploit this SQL injection flaw combined with PHP tag processing to achieve remote code execution on the server.
Problem types
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Any version before 4.4.10
Credits
Arthur Deloffre (Vozec)
Louka Jacques-Chevallier (Laluka)
References
blog.spip.net/...jour-de-securite-sortie-de-SPIP-4-4-10.html
git.spip.net/spip/spip
www.vulncheck.com/...ip-sql-injection-rce-via-union-php-tags