Candidate: CVE-2020-28984 PublicDate: 2020-11-23 22:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28984 https://git.spip.net/spip/spip/commit/ae4267eba1022dabc12831ddb021c5d6e09040f8 https://git.spip.net/spip/spip/compare/v3.2.7...v3.2.8 Description: prive/formulaires/configurer_preferences.php in SPIP before 3.2.8 does not properly validate the couleur, display, display_navigation, display_outils, imessage, and spip_ecran parameters. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_spip: upstream_spip: needs-triage precise/esm_spip: DNE trusty_spip: ignored (out of standard support) trusty/esm_spip: DNE xenial_spip: ignored (end of standard support, was needs-triage) bionic_spip: needs-triage focal_spip: needs-triage groovy_spip: ignored (reached end-of-life) hirsute_spip: not-affected (3.2.8-1) impish_spip: not-affected (3.2.8-1) jammy_spip: not-affected (3.2.8-1) devel_spip: not-affected (3.2.8-1)