VDB
CVE-2021-44122
CVE-2021-44122
PUBLISHED
CVSS 8.800000190734863 HIGH
SPIP 4.0.0 is affected by a Cross Site Request Forgery (CSRF) vulnerability in ecrire/public/aiguiller.php, ecrire/public/balises.php, ecrire/balise/formulaire_.php. To exploit the vulnerability, a visitor must visit a malicious website which redirects to the SPIP website. It is also possible to combine XSS vulnerabilities in SPIP 4.0.0 to exploit it. The vulnerability allows an authenticated attacker to execute malicious code without the knowledge of the user on the website (CSRF).
EPSS 0.22% · 44.8th percentile
Risk Scores
CVSS 3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
0.22%
44.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| spip | spip | 4.0.0 |
| n/a | n/a | * |
Exploit Intelligence
Timeline
- Jan 26, 2022 CVE Published
- Jan 27, 2022 EPSS Score
- Feb 2, 2022 CVE Updated
- Mar 21, 2022 EPSS Score
- May 13, 2022 EPSS Score
- Jul 5, 2022 EPSS Score
- Aug 27, 2022 EPSS Score
- Oct 19, 2022 EPSS Score
- Dec 11, 2022 EPSS Score
- Feb 2, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 27, 2023 EPSS Score