Critical
CVSS 9.8
Overview
prive/formulaires/configurer_preferences.php in SPIP before 3.2.8 does not properly validate the couleur, display, display_navigation, display_outils, imessage, and spip_ecran parameters.
prive/formulaires/configurer_preferences.php in SPIP before 3.2.8 does not prope...
prive/formulaires/configurer_preferences.php in SPIP before 3.2.8 does not properly validate the couleur, display, display_navigation, display_outils, imessage, and spip_ecran parameters.
This vulnerability is rated 🔴 CRITICAL.
Recommended actions: