S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Sep 9, 2024

CVE-2024-7954 Scanner

CVE-2024-7954 scanner - Remote Code Execution vulnerability in SPIP Porte Plume Plugin

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.9k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-7954
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can execute arbitrary PHP as the SPIP user by sending a crafted HTTP request.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
SPIPby SPIP
AFFECTED< 4.3.0-alpha2SAFE ✓≥ 4.3.0-alpha2
spipby spip
AFFECTED< 4.3.0-alpha2SAFE ✓≥ 4.3.0-alpha2
Updated Aug 22, 2026View on NVD →
Detail

SPIP is a popular CMS used by website developers to manage online content efficiently. The Porte Plume Plugin enhances SPIP by providing a rich text editor for better content formatting. Used by organizations and individuals to manage content-rich websites, SPIP helps create, publish, and maintain digital assets. The plugin integrates seamlessly with SPIP's core functionality, allowing users to edit HTML without technical complexities. Porte Plume is integral to SPIP's text editing capabilities, offering users a flexible interface.

The SPIP Porte Plume Plugin is vulnerable to Remote Code Execution (RCE). A remote attacker can exploit this flaw without authentication to run arbitrary PHP code on the system. This type of vulnerability can give malicious users full control over the server. The critical nature of this issue requires immediate attention to prevent unauthorized access.

The vulnerability exists in the "porte_plume_previsu" action, where an attacker can send a specially crafted HTTP POST request. The "data" parameter in the request can be manipulated to inject malicious PHP code. Upon execution, the system processes this code, leading to arbitrary command execution. The vulnerable endpoint accepts crafted requests with minimal input validation, allowing remote users to exploit it. This flaw enables attackers to gain control of the server by executing system-level commands.

Exploiting this vulnerability allows attackers to execute arbitrary code on the server. This could lead to complete server compromise, data theft, or further malware deployment. Unauthorized code execution can impact system integrity, lead to sensitive information disclosure, and allow the installation of backdoors. Additionally, attackers could use the compromised server to launch further attacks on connected systems.

By using the S4E platform, you gain access to continuous vulnerability assessments and detailed reports on exposed weaknesses. The platform automates vulnerability scanning, saving you time and effort in maintaining security. Our tools help you stay ahead of emerging threats with up-to-date information and real-time alerts. Additionally, you can track and remediate security issues across all your digital assets from a single platform. Join now to protect your digital infrastructure with proactive threat management.

References:

Solution Advice
  • Update SPIP to the latest version (4.30-alpha2, 4.2.13, or 4.1.16).
  • Restrict access to the vulnerable endpoint.
  • Regularly audit plugins and external components for security patches.
  • Implement web application firewalls to detect and block suspicious requests.
  • Monitor server logs for any unusual activity.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.