CVE-2019-11071

Published
View on NVD ↗
CVSS v3
N/A
CVSS v2
6.5
MEDIUM
Affected
1
PROJECT

Description

SPIP 3.1 before 3.1.10 and 3.2 before 3.2.4 allows authenticated visitors to execute arbitrary code on the host server because var_memotri is mishandled.

spip/spip
spip/spipUNAVAILABLE
SPIP Core
GitHubGitHub
82