OSV 1.4.0 · unreviewed · 修改于 2026-08-21 08:31
发布时间
2026-08-21 08:31
GitHub 审查时间
—
NVD 发布时间
2026-08-21 07:16
源文件
advisories/unreviewed/2026/08/GHSA-wj6g-rh9q-6vvm/GHSA-wj6g-rh9q-6vvm.json
SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to incorrect identification of <?php blocks, and var_export's mishandling of certain cases such as presence of a '<' character.
该公告没有提供结构化的受影响软件包信息。