SPIP 3.1.x suffers from a Reflected Cross Site Scripting Vulnerability in /ecrire/exec/puce_statut.php involving the $id parameter, as demonstrated by a /ecrire/?exec=puce_statut URL.
| Software | From | Fixed in |
|---|---|---|
| spip / spip | 3.1.0-alpha | 3.1.0-alpha.x |
| spip / spip | 3.1.0-rc3 | 3.1.0-rc3.x |
| spip / spip | 3.1.0-rc | 3.1.0-rc.x |
| spip / spip | 3.1.0 | 3.1.0.x |
| spip / spip | 3.1.3 | 3.1.3.x |
| spip / spip | 3.1.1 | 3.1.1.x |
| spip / spip | 3.1.0-rc2 | 3.1.0-rc2.x |
| spip / spip | 3.1.2 | 3.1.2.x |
| spip / spip | 3.1.0-beta | 3.1.0-beta.x |