VDB
CVE-2019-16391
CVE-2019-16391
PUBLISHED
CVSS 6.5 MEDIUM
SPIP before 3.1.11 and 3.2 before 3.2.5 allows authenticated visitors to modify any published content and execute other modifications in the database. This is related to ecrire/inc/meta.php and ecrire/inc/securiser_action.php.
EPSS 1.49% · 72.2th percentile
Risk Scores
CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS Score
1.49%
72.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:16.04:LTS | spip | 0, 3.0.20-1, 3.0.21-1 |
| Ubuntu:18.04:LTS | spip | 0, 3.1.4-3 |
Timeline
- Sep 17, 2019 CVE Published
- Sep 25, 2019 CVE Updated
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Dec 28, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Mar 1, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Jul 4, 2022 EPSS Score
- Sep 6, 2022 EPSS Score
References
- https://ubuntu.com/security/CVE-2019-16391 third-party-advisory
- https://git.spip.net/SPIP/spip/commit/187952ce85e73b52c2753f2d54fc2c44807b8f79 third-party-advisory
- https://git.spip.net/SPIP/spip/commit/3cbc758400323ab006c00ea78eacdb8f76aa5f66 third-party-advisory
- https://blog.spip.net/Mise-a-jour-CRITIQUE-de-securite-Sortie-de-SPIP-3-2-5-et-SPIP-3-1-11.html third-party-advisory
- https://ubuntu.com/security/notices/USN-4536-1 vendor-advisory
- https://www.cve.org/CVERecord?id=CVE-2019-16391 third-party-advisory