CVE-2024-7954
SPIP porte_plume Plugin Arbitrary PHP Execution
The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can execute arbitrary PHP as the SPIP user by sending a crafted HTTP request.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
SPIP · SPIPpublic PoCs found — 10
githubgithub.com/Chocapikk/CVE-2024-7954★ 13githubgithub.com/gh-ost00/CVE-2024-7954-RCE★ 9githubgithub.com/bigb0x/CVE-2024-7954★ 6githubgithub.com/TheCyberguy-17/RCE_CVE-2024-7954★ 5githubgithub.com/0dayan0n/RCE_CVE-2024-7954-★ 2githubgithub.com/ShivanshKuntal/Exploitation-of-a-Remote-Code-Execution-vulnerability--CVE-2024-7954-★ 1githubgithub.com/zxj-hub/CVE-2024-7954POC★ 0githubgithub.com/Arthikw3b/RCE-CVE-2024-7954★ 0githubgithub.com/r0otk3r/CVE-2024-7954★ 0cve_referencethinkloveshare.com/hacking/spip_preauth_rce_2024_part_1_the_feather/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →