SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1.
php
exploit
deserialization
poc
rce
vulnerability
nuclei
spip
cve
web-hacking
remote-code-execution
nuclei-templates
cve-2023-27372
cve2023
-
Updated
Oct 13, 2024 - Python