Security Advisory

CVE-2023-24258

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-02-27 00:00:00
Last updated 2025-03-11 03:00:35
Assigner mitre
State PUBLISHED

Description

SPIP v4.1.5 and earlier was discovered to contain a SQL injection vulnerability via the _oups parameter. This vulnerability allows attackers to execute arbitrary code via a crafted POST request.