Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 06 Oct 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Crayons plugin for SPIP before 3.5.0 contains a missing authorization vulnerability that allows unauthenticated attackers to modify arbitrary editable object fields by omitting the secu_ anti-forgery parameter in crayons_store.php, causing the authorization dispatcher to resolve an unconditionally-true handler instead of the proper modification check. Attackers can chain this flaw to write a malicious .html skeleton file, disclose sensitive configuration files containing the site secret, and forge a signed ajax context to execute the uploaded skeleton, achieving arbitrary PHP code execution as the web-server user. | |
| Title | SPIP Crayons Plugin < 3.5.0 Authorization Bypass RCE | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-06T16:16:07.042Z
Reserved: 2026-10-01T18:02:50.082Z
Link: CVE-2026-104070
No data.
Status : Awaiting Analysis
Published: 2026-10-06T17:17:12.213
Modified: 2026-10-06T20:05:55.733
Link: CVE-2026-104070
No data.
OpenCVE Enrichment
Updated: 2026-10-06T18:00:05Z
-
CWE-862
Missing Authorization