SPIP before 4.3.6, 4.2.17, and 4.1.20 allows unauthorized content disclosure in the private area. The application does not properly check authorization when displaying content of articles and sections (rubriques) in AJAX-loaded fragments, allowing an authenticated attacker to access restricted content. This vulnerability is not mitigated by the SPIP security screen.
Metrics
Affected Vendors & Products
References
History
Thu, 19 Feb 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SPIP before 4.3.6, 4.2.17, and 4.1.20 allows unauthorized content disclosure in the private area. The application does not properly check authorization when displaying content of articles and sections (rubriques) in AJAX-loaded fragments, allowing an authenticated attacker to access restricted content. This vulnerability is not mitigated by the SPIP security screen. | |
| Title | SPIP < 4.3.6 Authorization Bypass Leading to Content Disclosure | |
| First Time appeared |
Spip
Spip spip |
|
| CPEs | cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Spip
Spip spip |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-19T14:58:14.582Z
Reserved: 2026-02-19T03:00:22.782Z
Link: CVE-2025-71242
No data.
Status : Received
Published: 2026-02-19T16:27:12.113
Modified: 2026-02-19T16:27:12.113
Link: CVE-2025-71242
No data.
OpenCVE Enrichment
No data.