"value":"SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability in ecrire/public/interfaces.php, adding the function safehtml to the vulnerable fields. An editor is able to modify his personal information. If the editor has an article written and available, when a user goes to the public site and wants to read the author's information, the malicious code will be executed. The \"Who are you\" and \"Website Name\" fields are vulnerable."
},
{
"lang":"es",
"value":"SPIP versi\u00f3n 4.0.0 est\u00e1 afectado por una vulnerabilidad de tipo Cross Site Scripting (XSS) en el archivo ecrire/public/interfaces.php, que a\u00f1ade la funci\u00f3n safehtml a los campos vulnerables. Un editor es capaz de modificar su informaci\u00f3n personal. Si el editor presenta un art\u00edculo escrito y disponible, cuando un usuario vaya al sitio p\u00fablico y quiera leer la informaci\u00f3n del autor, ser\u00e1 ejecutado el c\u00f3digo malicioso. Los campos \"Who are you\" y \"Website Name\" son vulnerables"