Alerts This Week
Warning Icon 1 717
Alerts This Week
Warning Icon 1 717

Ubuntu 16.04 LTS SPIP Critical XSS SQL PHP Flaws USN-8150-1

ubuntu
Calendar Grey April 6, 2026
Dist Ubuntu Esm H88
Several security fixes for SPIP in Ubuntu 16.04 LTS address critical threats including SQL injection and XSS.
Several security issues were fixed in SPIP.

Summary

Several security issues were fixed in SPIP.

Software Description:

- spip: website engine for publishing

Details:

It was discovered that SPIP did not properly sanitize certain inputs. A

remote attacker could possibly use this issue to perform cross site

scripting. (CVE-2022-28959)

It was discovered that SPIP did not properly sanitize certain inputs. A

remote attacker could possibly use this issue to perform PHP injection

attacks. (CVE-2022-28960)

It was discovered that SPIP did not properly sanitize certain inputs. A

remote attacker could possibly use this issue to perform SQL injection

attacks. (CVE-2022-28961)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS
  spip                            3.0.21-1ubuntu1+esm1
                                  Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-8150-1

CVE-2022-28959, CVE-2022-28960, CVE-2022-28961

Severity
critical
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-8150-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here