CVE-2026-33549CWE-688
SPIP 4.4.10 through 4.4.12 before 4.4.13 allows unintended privilege assignment (of administrator privileges) during the editing of an author data structure…
Medium · published March 22, 2026
What it is
SPIP 4.4.10 through 4.4.12 before 4.4.13 allows unintended privilege assignment (of administrator privileges) during the editing of an author data structure because of STATUT mishandling.
The record
Technical detail
- CVSS v3.1
- 6.7 · MEDIUM
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L
- CVSS v4.0
- Not supplied
- EPSS
- 0.00239 · 14.9th percentile
- Weakness
- CWE-688 · Function Call With Incorrect Variable or Reference as Argument
- Published
- 2026-03-22T02:03Z
EPSS history
Timeline