← Back to CVE List

CVE-2024-8517

Published: 2024-09-06T16:15Z
Last Modified: 2024-09-18T18:05Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
SPIP before 4.3.2, 4.2.16, and 4.1.18 is vulnerable to a command injection issue. A remote and unauthenticated attacker can execute arbitrary operating system commands by sending a crafted multipart file upload HTTP request. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt