The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can execute arbitrary PHP as the SPIP user by sending a crafted HTTP request.
https://github.com/ghostycr/security-research-reports
https://github.com/r0otk3r/CVE-2024-7954
https://github.com/Arthikw3b/RCE-CVE-2024-7954
https://github.com/0dayan0n/RCE_CVE-2024-7954-
https://github.com/zxj-hub/CVE-2024-7954POC
https://github.com/issamiso/CVE-2024-7954
https://github.com/MuhammadWaseem29/RCE-CVE-2024-7954
https://github.com/TheCyberguy-17/RCE_CVE-2024-7954
https://github.com/3p1c0s3nd/exploitsYcves
https://github.com/fa-rrel/CVE-2024-7954-RCE