Feed/CVE-2024-7954
CVE-2024-7954CRITICALCVSS 9.8

CVE-2024-7954

Published Aug 23, 2024·Updated Jun 17, 2026

NVD Description

The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can execute arbitrary PHP as the SPIP user by sending a crafted HTTP request.

Public Exploits & PoCs7 found

PoC: CVE-2024-7954

Unauthenticated Remote Code Execution in SPIP versions up to and including 4.2.12

3

PoC: CVE-2024-7954

This exploit will attempt to execute system commands on SPIP targets.

2

PoC: CVE-2024-7954

The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can execute arbitrary PHP as the SPIP user by sending a crafted HTTP request.

1

PoC: Exploitation-of-a-Remote-Code-Execution-vulnerability--CVE-2024-7954-

Exploitation of a Remote Code Execution vulnerability- (CVE-2024-7954)

PoC: RCE_CVE-2024-7954-

The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can execute arbitrary PHP as the SPIP user by sending a crafted HTTP request. (CRITICAL)

PoC: CVE-2024-7954POC

SPIP 4.30-alpha2、4.2.13、4.1.16之前的版本使用的porte_plume插件存在任意代码执行漏洞,远程未经身份验证的攻击者可以通过发送精心设计的HTTP 请求以SPIP用户身份执行任意PHP代码。

PoC: CVE-2024-7954-RCE

Unauthenticated Remote Code Execution in SPIP versions up to and including 4.2.12

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free