VDB
CVE-2021-44122
CVE-2021-44122
PUBLISHED
CVSS 8.800000190734863 HIGH
SPIP 4.0.0 is affected by a Cross Site Request Forgery (CSRF) vulnerability in ecrire/public/aiguiller.php, ecrire/public/balises.php, ecrire/balise/formulaire_.php. To exploit the vulnerability, a visitor must visit a malicious website which redirects to the SPIP website. It is also possible to combine XSS vulnerabilities in SPIP 4.0.0 to exploit it. The vulnerability allows an authenticated attacker to execute malicious code without the knowledge of the user on the website (CSRF).
EPSS 0.49% · 40.4th percentile
Risk Scores
CVSS 3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
0.49%
40.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| spip | spip | 4.0.0 |
| n/a | n/a | * |
Timeline
- Jan 26, 2022 CVE Published
- Jan 27, 2022 EPSS Score
- Feb 2, 2022 CVE Updated
- Mar 21, 2022 EPSS Score
- May 13, 2022 EPSS Score
- Jul 5, 2022 EPSS Score
- Aug 28, 2022 EPSS Score
- Oct 20, 2022 EPSS Score
- Dec 12, 2022 EPSS Score
- Feb 3, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 28, 2023 EPSS Score