SPIP vulnerability

SPIP before 4.4.18 contains a mass assignment vulnerability in the editer_objet action that allows unauthenticated attackers to write arbitrary rows to any SQL table lacking a champs_editables allowlist by supplying an attacker-controlled arg parameter resolving to internal database tables. Attackers can insert a malicious row into the spip_jobs queue with a controlled PHP function and arguments, which is then dynamically executed when the cron processes the queue, resulting in remote code execution.

Published 11 Sep 2026Updated 15 Sep 20263 sources
CVSS 9.3

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.