RULE(RULE ID:338392)

Rule General Information
Release Date: 2024-09-03
Rule Name: SPIP porte_plume Plugin Arbitrary Code Execution Vulnerability (CVE-2024-7954)
Severity:
CVE ID:
Rule Protection Details
Description: SPIP porte_plume plugin arbitrary code execution vulnerability (cve-2024-7954).
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference: https://vulncheck.com/advisories/spip-porte-plume
https://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-3-0-alpha2-SPIP-4-2-13-SPIP-4.html
https://thinkloveshare.com/hacking/spip_preauth_rce_2024_part_1_the_feather/
https://cxsecurity.com/cveshow/CVE-2024-7954/
Solutions
Refer to the announcement or patch by the vendor: https://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-3-0-alpha2-SPIP-4-2-13-SPIP-4.html