Cross Site Scripting Vulnerability in SPIP by SPIP Team
CVE-2021-44120
5.4MEDIUM
What is CVE-2021-44120?
SPIP version 4.0.0 contains a Cross Site Scripting vulnerability located in ecrire/public/interfaces.php. This flaw enables an editor to alter personal details, which can be exploited when a user accesses the public site to view the author's information. Specifically, the fields 'Who are you' and 'Website Name' are affected, leading to potential execution of malicious scripts.