CVE-2024-7954 - SPIP Porte_plume Remote Code Execution (RCE)
<strong>CVE ID : </strong>CVE-2024-7954
<br>
<strong>Published : </strong> Aug. 23, 2024, 6:15 p.m. | 10 hours, 36 minutes ago
<br>
<strong>Description : </strong>The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can execute arbitrary PHP as the SPIP user by sending a crafted HTTP request.
<br>
<strong>Severity:</strong> 9.8 | CRITICAL
<br>
Visit the link for more details, such as CVSS details, affected products, timeline, and more...