SPIP before 4.1.14 and 4.2.x before 4.2.8 allows XSS via the name of an uploaded file. This is related to javascript/bigup.js and javascript/bigup.utils.js.
CVE ID: CVE-2024-23659
Vendor: n/a
Product: n/a
EPSS Score: 1.01% (probability of being exploited)
EPSS Percentile: 76.02% (scored less or equal to compared to others)
EPSS Date: 2025-06-03 (when was this score calculated)
SSVC Exploitation: none
SSVC Technical Impact: partial
SSVC Automatable: false