SPIP before 4.1.14 and 4.2.x before 4.2.8 allows XSS via the name of an uploaded file. This is related to javascript/bigup.js and javascript/bigup.utils.js.
2024-01-19T05:15:09.233
2025-06-02T15:15:32.007
Modified
CVSSv3.1: 6.1 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | spip | spip | < 4.1.14 | Yes |
| Application | spip | spip | < 4.2.8 | Yes |