← Back

CVE-2016-9997

nvd nist
Published: Dec 17, 2016Modified: May 6, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

SPIP 3.1.x suffers from a Reflected Cross Site Scripting Vulnerability in /ecrire/exec/puce_statut.php involving the `$id` parameter, as demonstrated by a /ecrire/?exec=puce_statut URL.

Affected (9)

Products: Spip: Spip
1 product
Spip
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Spip
Version 3.1.0
Version 3.1.0 alpha
Version 3.1.0 beta
Version 3.1.0 rc2
Version 3.1.0 rc3
Version 3.1.0 rc
Version 3.1.1
Version 3.1.2
Version 3.1.3

References (6)

Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Issue TrackingPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchVendor Advisory

Timeline

No history available yet.