CVE-2023-27372 is an unauthenticated remote code execution vulnerability in SPIP affecting versions before 4.2.1, with fixes also released for supported branches as 3.2.18, 4.0.10, and 4.1.8. The flaw is reachable from the public-facing area of the application, including the password reset workflow, and is associated with mishandled serialization of form values. Available context indicates exploitation through the oubli parameter and describes the issue as a template-injection-style path that can lead to server-side execution of attacker-controlled code during request processing.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
8 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (3 hidden).
Repository contains a single Python exploit script (CVE-2023-27372.py) and a README. The script is an unauthenticated RCE exploit for SPIP versions prior to 4.2.1, abusing PHP object injection via the password reset form parameter 'oubli' on /spip.php?page=spip_pass. Core flow: - get_csrf_token(url): Performs an HTTP GET to /spip.php?page=spip_pass and parses the HTML to extract the anti-CSRF token from input[name=formulaire_action_args]. - run_command(url, csrf_token, command): Sends an HTTP POST to the same endpoint with formulaire_action=oubli and a crafted serialized string placed in 'oubli' that contains PHP code invoking system('<command>'). It then extracts command output from the reflected HTML using a regex against the raw response body. - interactive_shell(url): Verifies RCE by running 'id' and checking for 'uid=' in output, then provides an interactive prompt loop. It refreshes the CSRF token before each command because SPIP regenerates it. Exploit capability: arbitrary command execution as the web server user with output returned inline (no reverse shell or persistence). The only network target is the SPIP password reset endpoint; no hardcoded external C2, IPs, or domains are present.
This repository contains a Python exploit script (exploit.py) and a brief readme. The exploit targets a remote code execution (RCE) vulnerability in the SPIP CMS, specifically via the /spip/spip.php?page=spip_pass endpoint. The script takes a target URL as an argument, fetches a required form token, and then submits a POST request with a malicious PHP payload that executes an arbitrary system command provided by the user. The output of the command is displayed in the response. The exploit is operational and requires the attacker to have network access to the target's web interface. The repository is simple, with a single exploit script and no additional modules or framework dependencies.
This repository contains a Python exploit script (cve.py) targeting CVE-2023-27372, a critical unauthenticated remote code execution vulnerability in SPIP CMS versions prior to 4.2.1. The exploit abuses a cache poisoning flaw in the password reset mechanism, specifically the 'oubli' parameter in the /spip.php?page=spip_pass endpoint, to inject arbitrary PHP code into the cache file (ecrire/data/cache/reset_cache.php). The script automates the process of fetching the required anti-CSRF token, crafting a serialized payload, and delivering it to the vulnerable endpoint. Upon successful exploitation, a PHP web shell (default: pwnd.php, customizable) is uploaded to the server, granting the attacker command execution capabilities. The script also verifies the shell upload and attempts to gather basic system information from the compromised host. The repository consists of a detailed README.md and a single Python exploit script, with the latter being the main entry point and containing all exploit logic. No framework is used; the exploit is standalone and operational, providing a working web shell payload.
This repository contains a single Metasploit module (spip_rce_form.rb) that exploits a PHP code injection vulnerability (CVE-2023-27372) in the SPIP content management system. The exploit targets the 'oubli' parameter in a POST request to the 'spip.php?page=spip_pass&lang=fr' endpoint, allowing unauthenticated remote code execution as the web server user. The module supports payloads for PHP, Unix/Linux, and Windows platforms, and can deliver Meterpreter or command shell payloads. The exploit is weaponized, requiring only network access to the target's web interface and no authentication. The code is structured as a standard Metasploit module, with methods for version checking, payload delivery, and exploitation. The only fingerprintable endpoint is the SPIP password reset page, which is used to deliver the payload.
This repository contains a working proof-of-concept exploit for CVE-2023-27372, a remote code execution (RCE) vulnerability in SPIP versions prior to 4.2.1. The vulnerability is due to unsafe deserialization in the password reset feature, specifically in the 'protege_champ' function, which improperly validates and unserializes user input. The exploit is implemented in Python (exploit.py) and automates the attack by: - Fetching a CSRF token from the vulnerable endpoint (/spip.php?page=spip_pass) - Crafting a malicious serialized PHP payload that injects arbitrary PHP code - Sending the payload to the target via a POST request - Providing an interactive shell for ongoing command execution if exploitation is successful The repository includes a README.md explaining the vulnerability, exploitation method, and a suggested patch. The requirements.txt lists Python dependencies (requests, lxml). The main entry point is exploit.py, which is a standalone exploit script. The exploit targets network-accessible SPIP installations and requires only the target URL as input. No hardcoded endpoints or IPs are present, but the attack is performed against the /spip.php?page=spip_pass endpoint on the target server.
This repository contains a Python exploit script (CVE-2023-27372.py) targeting CVE-2023-27372, a remote code execution vulnerability in the SPIP CMS. The exploit works by sending HTTP requests to the /spip.php?page=spip_pass endpoint of a target SPIP installation, extracting a CSRF token, and then submitting a crafted payload that injects PHP code (demonstrated with 'whoami'). If successful, the script confirms code execution by analyzing the server's response. The repository also includes a README.md with French-language instructions for installation and usage. The exploit is operational, providing a working proof-of-concept for remote code execution, and is intended for educational and testing purposes only.
This repository provides a proof-of-concept (PoC) exploit for CVE-2023-27372, a critical unauthenticated remote code execution vulnerability in SPIP CMS versions prior to 4.2.1 (excluding certain fixed versions). The main exploit is implemented in 'CVE-2023-27372.py', a Python script that automates the exploitation process by first retrieving an anti-CSRF token from the password reset page ('/spip.php?page=spip_pass'), then submitting a specially crafted payload via the 'oubli' parameter to inject and execute arbitrary PHP code on the server. The payload allows execution of arbitrary system commands as the web server user. The repository also includes a Nuclei detection template ('CVE-2023-27372.yaml'), a Dockerfile for setting up a vulnerable SPIP environment, and a README.md with detailed vulnerability explanation, usage instructions, and references. The attack vector is network-based, requiring only HTTP access to the vulnerable endpoint. The exploit does not require authentication and targets a specific form parameter in the password reset functionality. The repository is structured for both exploitation and detection, with clear documentation and setup instructions.
This repository provides two exploit implementations for CVE-2023-27372, a remote code execution vulnerability in SPIP CMS versions prior to 4.2.1. The vulnerability exists in the password recovery form (spip.php?page=spip_pass), which fails to properly sanitize user input, allowing attackers to inject and execute arbitrary PHP code via the 'oubli' parameter. The repository contains: - CVE-2023-27372.py: A Python script that can scan single or multiple SPIP URLs for the vulnerability, optionally using LeakIX to discover targets. If a target is vulnerable, it provides an interactive shell for command execution via the web interface. - spip_oubli_param_rce.rb: A Metasploit module that automates exploitation, allowing for arbitrary payload execution and integration with the Metasploit framework. - requirements.txt: Lists Python dependencies for the scanner. - README.md: Documentation and usage instructions. Both exploit implementations work by retrieving a CSRF token from the password reset page, crafting a serialized PHP payload, and sending it via POST to the vulnerable endpoint. Successful exploitation grants remote code execution as the web server user. The repository is operational and can be used for both vulnerability detection and exploitation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unauthenticated remote code execution vulnerability in the SPIP CMS that the walkthrough uses to gain initial access by uploading a web shell.
An unauthenticated remote code execution vulnerability in SPIP, affecting SPIP 4.2.0 in the content, exploitable via the oubli parameter in the password reset form.
An unauthenticated remote code execution vulnerability in SPIP (core) previously exploited via template injection (notably through the password reset flow using the `oubli` parameter), where unsanitized input reached a template rendering path with `interdire_scripts=false`, enabling PHP tag injection and server-side execution.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.