PT-2026-20840 · Spip · Spip

CVE-2025-71242

·

Published

2025-01-01

·

Updated

2026-02-23

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SPIP versions prior to 4.3.6 SPIP versions prior to 4.2.17 SPIP versions prior to 4.1.20
Description The application does not properly verify authorization when displaying content of articles and sections (rubriques) in AJAX-loaded fragments, which allows an authenticated attacker to access restricted content. The SPIP security screen does not mitigate this issue.
Recommendations Update to SPIP version 4.3.6 or later. Update to SPIP version 4.2.17 or later. Update to SPIP version 4.1.20 or later.

Exploit

Fix

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-71242

Affected Products

Spip