DEBIAN-CVE-2026-72710

    Dashboard / Vulnerabilities / DEBIAN-CVE-2026-72710

    DEBIAN-CVE-2026-72710

    Published: 11 Sept 2026Last Modified: 12 Sept 2026
    Upstream:

    Summary:

    Details: SPIP before 4.4.18 contains a remote code execution vulnerability in the editer_objet action where the arg parameter resolves SQL table names without enforcing an editable columns allowlist, allowing attackers with a valid nonce to inject attacker-controlled rows into the spip_jobs table. Attackers can supply arg=job/0 with crafted fonction and args values, which are later unserialized and executed when the cron job queue is drained, resulting in arbitrary PHP function execution on the underlying system.

    Affected packages

    Package

    Name: spip

    Purl: pkg:deb/debian/spip?arch=source&distro=trixie

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -4.4.19+dfsg-0+deb13u1

    Affected versions

    4.4.10+dfsg-1
    4.4.11+dfsg-0+deb13u1
    4.4.11+dfsg-1
    4.4.13+dfsg-0+deb13u1
    4.4.13+dfsg-1
    4.4.14+dfsg-1
    4.4.15+dfsg-0+deb13u1
    4.4.15+dfsg-1
    4.4.16+dfsg-0+deb13u1
    4.4.16+dfsg-1
    4.4.18+dfsg-1
    4.4.3+dfsg-1
    4.4.3+dfsg-1+deb13u1
    4.4.4+dfsg-1
    4.4.5+dfsg-1
    4.4.6+dfsg-1
    4.4.7+dfsg-1
    4.4.8+dfsg-1
    4.4.9+dfsg-1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    DEBIAN-CVE-2026-72710 | CVE-DB