VYPR
Medium severity5.4NVD Advisory· Published Jan 26, 2022· Updated Jun 17, 2026

CVE-2021-44120

CVE-2021-44120

Description

SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability in ecrire/public/interfaces.php, adding the function safehtml to the vulnerable fields. An editor is able to modify his personal information. If the editor has an article written and available, when a user goes to the public site and wants to read the author's information, the malicious code will be executed. The "Who are you" and "Website Name" fields are vulnerable.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Spip/Spip3 versions
    cpe:2.3:a:spip:spip:4.0.0:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:spip:spip:4.0.0:*:*:*:*:*:*:*
    • (no CPE)range: = 4.0.0
    • (no CPE)

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.