Cross-Site Scripting Vulnerability in SPIP by SPIP team
CVE-2025-71241
What is CVE-2025-71241?
The SPIP content management system versions prior to 4.3.6, 4.2.17, and 4.1.20 are susceptible to a Cross-Site Scripting (XSS) vulnerability. This issue arises in the private area of the application, specifically through an inadequately sanitized error message generated by the 'transmettre' API. Attackers can exploit this flaw by injecting malicious scripts, potentially compromising the integrity of the application. Mitigation is available through the implementation of the SPIP security screen.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SPIP 4.1.0 < 4.1.20
SPIP 4.2.0 < 4.2.17
SPIP 4.3.0 < 4.3.6
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
