FixVibe

// sondagens / holofote

SPIP valider_xml XSS Exposure

A legacy SPIP utility page should not reflect URL input into HTML.

A pegada

Older SPIP installations still appear on inherited marketing sites, community portals, and CMS estates. CVE-2016-7981 affects SPIP 3.1.2 and earlier when valider_xml reflects URL input into an HTML response without the expected encoding.

Como funciona

This active check confirms whether user-controlled input or workflow behavior crosses a security boundary. Public docs keep the explanation high-level so customers understand the risk. For check-specific questions about exact detection heuristics, active payload details, or source-code rule patterns, contact support@fixvibe.app.

O raio de impacto

If the affected endpoint is reachable, a crafted link may execute attacker-controlled script in a victim's browser under the SPIP site's origin. The practical impact depends on authentication state, cookie flags, administrative exposure, and what sensitive actions or data the SPIP origin can reach.

// what fixvibe checks

What FixVibe checks

FixVibe checks this class with verified-domain active testing that is bounded, non-destructive, and evidence-driven. Public reports describe the affected surface and remediation. For check-specific questions about exact detection heuristics, active payload details, or source-code rule patterns, contact support@fixvibe.app.

Defesas blindadas

Upgrade SPIP to 3.1.3 or newer. During rollout, restrict access to SPIP authoring/admin surfaces and ensure any remaining valider_xml output validates URL parameters and HTML-encodes reflected values before rendering.

// rode no seu próprio app

Continue publicando enquanto o FixVibe vigia.

O FixVibe pressiona a superfície pública do seu app do jeito que um atacante faria — sem agente, sem instalação, sem cartão. Continuamos pesquisando novos padrões de vulnerabilidade e transformando isso em checks práticos e fixes prontos para Cursor, Claude e Copilot.

Sondagens ativas
108
testes nessa categoria
módulos
30
checks dedicados de sondagens ativas
todo scan
397+
testes em todas as categorias
  • Grátis — sem cartão, sem instalação, sem ping de Slack
  • Só colar uma URL — a gente crawla, sonda e reporta
  • Achados classificados por severidade, deduplicados no sinal
  • Prompts de fix atuais, prontos para colar no Cursor, Claude, Copilot
Rodar um scan grátis

// checks atuais · fixes práticos · publique com confiança

SPIP valider_xml XSS Exposure — Holofote de Vulnerabilidade | FixVibe · FixVibe