Attacker Impact
CVE-2016-7980 affects SPIP 3.1.2 and earlier in the XML validator workflow [S1]. A remote attacker can try to induce an authenticated administrator's browser to submit a crafted validator request, which can run the XML validator against a local file [S1]. NVD also notes that this CSRF issue can be combined with CVE-2016-7998 in affected deployments to reach arbitrary PHP code execution under the right authenticated workflow conditions [S1][S2].
Root Cause
The affected SPIP releases exposed an administrative valider_xml workflow without sufficient request-forgery protection for that action [S1]. The related template compiler issue affects the same SPIP 3.1.2-and-earlier release range and depends on authenticated authoring/template behavior [S2].
Concrete Fixes
Upgrade SPIP to 3.1.3 or a newer supported release, or apply the vendor security patches for the deployed release line [S1][S2]. During rollout, restrict the ecrire administrative surface to trusted users or networks, keep upload and template-management permissions limited to trusted administrators, and verify the runtime version on the server rather than relying only on public generator banners.
Covered by FixVibe
FixVibe flags public SPIP sites that identify release 3.1.2 or earlier and cites CVE-2016-7980 alongside the related SPIP 2016 advisories. After upgrading, remove any stale public version banner.
