Preliminary research
Casse-Spip - From an Unauthenticated SQL Injection to Remote Command Execution
AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.
SPIP vulnerabilities combine an unauthenticated SQL injection, missing action authorization and mass assignment. The article explains how these flaws enable administrator account takeover or command execution through the job queue, and records the fixes in SPIP 4.4.18.
Record
- Researcher
- Franck Chevalier
- Published by
- blog.lexfo.fr
- Topic
- Injection
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Franck Chevalier, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .