Debian Security Advisory

DLA-738-1 spip -- LTS security update

Date Reported:
08 Dec 2016
Affected Packages:
spip
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 847156.
In Mitre's CVE dictionary: CVE-2016-9152.
More information:

It was discovered that there was a cross-site scripting (XSS) vulnerability in spip, a website publishing engine, which allowed remote attackers to inject arbitrary web script or HTML via the rac parameter.

For Debian 7 Wheezy, this issue has been fixed in spip version 2.1.17-1+deb7u7.

We recommend that you upgrade your spip packages.