
SPIP 4.30-alpha2、4.2.13、4.1.16之前的版本使用的porte_plume插件存在任意代码执行漏洞,远程未经身份验证的攻击者可以通过发送精心设计的HTTP 请求以SPIP用户身份执行任意PHP代码。
The porte_plume plugin used in SPIP versions before 4.30-alpha2, 4.2.13, and 4.1.16 has an arbitrary code execution vulnerability. Remote unauthenticated attackers can execute arbitrary PHP code as SPIP users by sending specially crafted HTTP requests.