CVE-2025-71242

SPIP before 4.3.6, 4.2.17, and 4.1.20 allows unauthorized content disclosure in the private area. The application does not properly check authorization when displaying content of articles and sections (rubriques) in AJAX-loaded fragments, allowing an authenticated attacker to access restricted content. This vulnerability is not mitigated by the SPIP security screen.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:03

Type Values Removed Values Added
Summary
  • (es) SPIP antes de 4.3.6, 4.2.17 y 4.1.20 permite la divulgación no autorizada de contenido en el área privada. La aplicación no verifica correctamente la autorización al mostrar contenido de artículos y secciones (rubriques) en fragmentos cargados por AJAX, lo que permite a un atacante autenticado acceder a contenido restringido. Esta vulnerabilidad no es mitigada por la pantalla de seguridad de SPIP.

02 Mar 2026, 15:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 4.3
v2 : unknown
v3 : 6.5

24 Feb 2026, 19:25

Type Values Removed Values Added
References () https://blog.spip.net/Mise-a-jour-de-securite-sortie-de-SPIP-4-3-6.html - () https://blog.spip.net/Mise-a-jour-de-securite-sortie-de-SPIP-4-3-6.html - Broken Link
References () https://git.spip.net/spip/spip - () https://git.spip.net/spip/spip - Product
References () https://www.vulncheck.com/advisories/spip-authorization-bypass-leading-to-content-disclosure - () https://www.vulncheck.com/advisories/spip-authorization-bypass-leading-to-content-disclosure - Third Party Advisory
First Time Spip spip
Spip
CPE cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:*

20 Feb 2026, 21:19

Type Values Removed Values Added
CWE CWE-285

19 Feb 2026, 16:27

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-19 16:27

Updated : 2026-06-17 10:03


NVD link : CVE-2025-71242

Mitre link : CVE-2025-71242

CVE.ORG link : CVE-2025-71242


JSON object : View

Products Affected

spip

  • spip
CWE
CWE-285

Improper Authorization