SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1.
php exploit deserialization poc rce vulnerability nuclei spip cve web-hacking remote-code-execution nuclei-templates cve-2023-27372 cve2023
-
Updated
Oct 13, 2024 - Python