important · Web applicationsTwo newly disclosed SPIP core flaws permit pre-authentication server-side code execution.AffectsSPIP, an open-source content-management system running public websites on PHP web serversSPIP 4.4.22 fixes both paths, and the project's separate security-screen mechanism does not cover them.Detail and 2 sourcesSourcesResearchMise à jour critique de sécurité : sortie de SPIP 4.4.22 - SPIP BlogResearchMultiples vulnérabilités dans SPIP - CERT-FRCopy linkShare this findingEmailHacker NewsRedditMastodonBlueskyXLinkedInFacebookCopy link