CVE-2020-28984
Vulnerability Scoring
Attack Complexity Details
- Attack Complexity: Low Impact
- Attack Vector: NETWORK
- Privileges Required: None
- Scope: UNCHANGED
- User Interaction: NONE
CIA Impact Definition
- Confidentiality: HIGH IMPACT
- Integrity: HIGH IMPACT
- Availability: HIGH IMPACT
CVE-2020-28984 Vulnerability Summary
prive/formulaires/configurer_preferences.php in SPIP before 3.2.8 does not properly validate the couleur, display, display_navigation, display_outils, imessage, and spip_ecran parameters.
Access Complexity Graph for CVE-2020-28984
Impact Analysis for CVE-2020-28984
CVE-2020-28984: Detailed Information and External References
EPSS
0.00172
EPSS %
0.55104
References
0.00172
- https://git.spip.net/spip/spip/commit/ae4267eba1022dabc12831ddb021c5d6e09040f8
- https://git.spip.net/spip/spip/compare/v3.2.7...v3.2.8
- https://lists.debian.org/debian-lts-announce/2020/12/msg00036.html
- https://www.debian.org/security/2020/dsa-4798
CWE
NVD-CWE-noinfo
Vulnerable Configurations
-
cpe:2.3:a:spip:spip:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.0.0:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.0.1:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.0.2:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.0.2:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.0.3:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.0.3:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.0.4:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.0.4:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.0.5:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.0.5:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.0.6:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.0.6:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.0.7:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.0.7:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.0.8:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.0.8:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.0.9:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.0.9:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.0.10:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.0.10:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.0.11:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.0.11:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.0.12:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.0.12:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.0.13:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.0.13:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.0.14:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.0.14:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.0.15:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.0.15:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.0.16:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.0.16:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.0.17:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.0.17:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.0.18:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.0.18:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.0.19:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.0.19:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.0.20:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.0.20:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.0.21:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.0.21:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.0.22:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.0.22:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.0.23:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.0.23:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.0.24:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.0.24:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.0.25:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.0.25:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.0.26:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.0.26:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.1.0:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.1.1:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.1.1:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.1.2:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.1.2:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.1.3:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.1.3:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.1.4:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.1.4:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.1.5:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.1.5:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.1.6:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.1.6:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.1.7:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.1.7:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.1.8:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.1.8:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.1.9:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.1.9:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.1.10:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.1.10:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.1.11:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.1.11:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.1.12:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.1.12:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.1.13:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.1.13:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.1.14:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.1.14:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.1.15:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.1.15:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.1.16:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.1.16:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.1.17:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.1.17:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.1.18:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.1.18:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.1.19:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.1.19:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.1.20:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.1.20:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.1.21:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.1.21:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.1.22:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.1.22:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.1.23:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.1.23:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.1.24:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.1.24:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.1.25:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.1.25:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.1.26:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.1.26:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.1.27:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.1.27:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.1.28:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.1.28:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.1.29:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.1.29:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:2.1.30:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.1.30:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.0.0:-:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.0.0:-:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.0.0:rc:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.0.0:rc:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.0.0:beta:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.0.0:beta:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.0.0:beta2:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.0.0:beta2:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.0.0:alpha1:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.0.0:alpha1:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.0.1:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.0.1:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.0.2:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.0.2:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.0.3:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.0.3:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.0.4:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.0.4:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.0.5:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.0.5:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.0.6:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.0.6:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.0.7:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.0.7:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.0.8:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.0.8:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.0.9:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.0.9:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.0.10:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.0.10:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.0.11:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.0.11:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.0.12:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.0.12:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.0.13:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.0.13:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.0.14:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.0.14:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.0.15:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.0.15:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.0.16:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.0.16:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.0.17:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.0.17:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.0.18:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.0.18:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.0.19:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.0.19:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.0.20:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.0.20:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.0.21:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.0.21:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.0.22:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.0.22:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.0.23:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.0.23:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.0.24:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.0.24:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.0.25:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.0.25:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.0.26:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.0.26:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.0.27:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.0.27:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.0.28:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.0.28:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.1.0:-:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.1.0:-:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.1.0:rc:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.1.0:rc:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.1.0:rc2:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.1.0:rc2:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.1.0:rc3:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.1.0:rc3:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.1.0:beta:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.1.0:beta:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.1.0:alpha:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.1.0:alpha:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.1.1:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.1.1:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.1.2:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.1.2:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.1.3:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.1.3:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.1.4:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.1.4:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.1.5:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.1.5:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.1.6:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.1.6:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.1.7:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.1.7:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.1.8:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.1.8:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.1.9:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.1.9:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.1.10:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.1.10:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.1.11:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.1.11:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.1.12:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.1.12:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.1.13:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.1.13:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.1.14:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.1.14:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.1.15:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.1.15:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.2.0:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.2.0:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.2.0:beta:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.2.0:beta:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.2.0:beta2:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.2.0:beta2:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.2.0:beta3:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.2.0:beta3:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.2.0:alpha:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.2.0:alpha:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.2.1:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.2.1:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.2.2:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.2.2:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.2.3:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.2.3:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.2.4:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.2.4:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.2.5:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.2.5:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.2.6:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.2.6:*:*:*:*:*:*:*
-
cpe:2.3:a:spip:spip:3.2.7:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:3.2.7:*:*:*:*:*:*:*
-
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
-
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
CVSS3 Source
nvd@nist.gov
CVSS3 Type
Primary
CVSS3 Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Protect Your Infrastructure: Combat Critical CVE Threats
Stay updated with real-time CVE vulnerabilities and take action to secure your systems. Enhance your cybersecurity posture with the latest threat intelligence and mitigation techniques. Develop the skills necessary to defend against CVEs and secure critical infrastructures. Join the top cybersecurity professionals safeguarding today's infrastructures.