Critical severity9.8NVD Advisory· Published Nov 23, 2020· Updated Jun 17, 2026
CVE-2020-28984
CVE-2020-28984
Description
prive/formulaires/configurer_preferences.php in SPIP before 3.2.8 does not properly validate the couleur, display, display_navigation, display_outils, imessage, and spip_ecran parameters.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- SPIP/SPIPdescription
Patches
Vulnerability mechanics
References
4- git.spip.net/spip/spip/commit/ae4267eba1022dabc12831ddb021c5d6e09040f8nvdPatchVendor Advisory
- git.spip.net/spip/spip/compare/v3.2.7...v3.2.8nvdRelease NotesVendor Advisory
- lists.debian.org/debian-lts-announce/2020/12/msg00036.htmlnvdMailing ListThird Party Advisory
- www.debian.org/security/2020/dsa-4798nvdThird Party Advisory
News mentions
0No linked articles in our index yet.