Preliminary research
Casse-Spip - From an Unauthenticated SQL Injection to Remote Command Execution
AI-collected research leads through 6 October 2026, including bounded month-by-month reviews of selected social and community sources from January through September. Unranked, incomplete, not community-vetted, and subject to change.
SPIP vulnerabilities combine an unauthenticated SQL injection, missing action authorization and mass assignment. The article explains how these flaws enable administrator account takeover or command execution through the job queue, and records the fixes in SPIP 4.4.18.
Record
- Researcher
- Franck Chevalier
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Franck Chevalier, first published at the original source. Preserved copies are kept so the citation survives its host.