S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-27372 Scanner

Detects 'Remote Code Execution (RCE)' vulnerability in SPIP affects v. before 4.2.1.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.1k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
1
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-27372
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

SPIP stands for Système de Publication pour l'Internet, and it is a free and open-source CMS (Content Management System) designed for building online magazines, collaborative projects, and corporate portals. SPIP is widely used for its user-friendly interface and robust features such as multilingual support, customizable templates, and advanced search tools. The CMS allows developers to manage and publish articles, blogs, forums, polls, and multimedia content, all with great ease and efficiency.

However, the CMS's version prior to 4.2.1 has a critical vulnerability known as CVE-2023-27372. This vulnerability occurs when SPIP mishandles serialization, which allows an attacker to execute remote code via form values in the public area. When exploited, the vulnerability gives an attacker the opportunity to perform actions as an authenticated user, leading to the complete compromise of the affected site.

CVE-2023-27372 can lead to significant consequences for organizations that use SPIP. For instance, an attacker could gain access to sensitive data, inject malware, deface the website, or use the compromised site to launch attacks on other websites. The vulnerability can also result in legal and reputational damage, as well as financial losses for organizations.

At s4e.io, we provide a platform that enables organizations to keep their digital assets secure and stay ahead of potential threats. With our pro features, organizations can quickly and easily learn about vulnerabilities in their websites and take proactive steps to address them. Our platform offers comprehensive security assessments, vulnerability scans, penetration testing, and security awareness training, among other services. Contact us today to learn more about how we can help keep your digital assets safe and secure.

 

REFERENCES

Solution Advice

To mitigate the risks posed by the vulnerability, organizations can take the following precautions:

  • Upgrade to the latest version of SPIP (3.2.18, 4.0.10, 4.1.8, or 4.2.1)
  • Implement firewalls and access controls to limit unauthorized access to the site
  • Use security plugins such as antivirus and web application firewalls
  • Regularly back up the site's data and monitor the website for any suspicious activity
  • Avoid using default passwords and keep all software up-to-date

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.