CVE-2024-8517 | SPIP up to 4.1.18/4.2.15/4.3.1 Multipart File Upload reliance on file name or extension of externally-supplied file (EUVD-2024-49235)
A vulnerability was found in SPIP up to 4.1.18/4.2.15/4.3.1. It has been declared as very critical. This vulnerability affects unknown code of the component Multipart File Upload Handler. Executing manipulation can lead to reliance on file name or extension of externally-supplied file.
This vulnerability is registered as CVE-2024-8517. It is possible to launch the attack remotely. Furthermore, an exploit is available.
It is recommended to upgrade the affected component.