CVE Field Guide
About Us
CVE-2026-48832
PUBLISHED
Assigner:
mitre
Reserved:
24.05.2026
Published:
24.05.2026
Updated:
24.05.2026
action/cookie.php in ecrire in SPIP before 4.4.15 is prone to an open redirect vulnerability.
Metrics
CVSS 3.1
CVSS Vector:
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N
CVSS Score:
3.5
CVSS score
3.5
Attack Vector
Network
Scope
Changed
Attack Complexity
High
Confidentiality Impact
None
Privileges Required
Low
Integrity Impact
Low
User Interaction
None
Availability Impact
None
CVSS 3.1
Product Status
Vendor
SPIP
Product
SPIP
Versions
Default:
unaffected
affected from 0 to 4.4.15 (excl.)
References
https://blog.spip.net/Mise-a-jour-de-securite-sortie-de-SPIP-4-4-15.html?lang=fr
https://git.spip.net/spip/spip/-/commit/75629034697ab52a963a340afd10930407e1cd55
https://git.spip.net/spip/ecrire/-/commit/a22cb8a56f1e37ff3854b73ff3f66aa3df47070a
Problem Types
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
CWE