Description
SPIP before 4.4.9 allows Stored Cross-Site Scripting (XSS) via syndicated sites in the private area. The #URL_SYNDIC output is not properly sanitized on the private syndicated site page, allowing an attacker who can set a malicious syndication URL to inject persistent scripts that execute when other administrators view the syndicated site details.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
4.4.0 (semver) before 4.4.9
Credits
Dorian Piette (Trachinus)
References
blog.spip.net/...-jour-de-securite-sortie-de-SPIP-4-4-9.html
git.spip.net/spip/spip
www.vulncheck.com/...oss-site-scripting-via-syndicated-sites (VulnCheck Advisory: SPIP < 4.4.9 Stored Cross-Site Scripting via Syndicated Sites)