SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1.
-
Updated
Oct 13, 2024 - Python
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1.
Metabase Pre-auth RCE (CVE-2023-38646)
Add a description, image, and links to the cve2023 topic page so that developers can more easily learn about it.
To associate your repository with the cve2023 topic, visit your repo's landing page and select "manage topics."