Medium severity6.5NVD Advisory· Published Dec 17, 2019· Updated Jun 17, 2026
CVE-2019-19830
CVE-2019-19830
Description
_core_/plugins/medias in SPIP 3.2.x before 3.2.7 allows remote authenticated authors to inject content into the database.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
- SPIP/SPIPdescription
Patches
Vulnerability mechanics
References
5- git.spip.net/SPIP/spip/commit/8eb11ba132b92696eb34d606d71aa8edf40e0f69nvdPatchVendor Advisory
- blog.spip.net/Mise-a-jour-CRITIQUE-de-securite-sortie-de-SPIP-3-2-7-SPIP-3-1-12.htmlnvdVendor Advisory
- usn.ubuntu.com/4536-1/nvdThird Party Advisory
- www.debian.org/security/2019/dsa-4583nvdThird Party Advisory
- zone.spip.net/trac/spip-zone/changeset/118898/spip-zone/_core_/plugins/mediasnvdBroken Link
News mentions
0No linked articles in our index yet.