CPE
The Crayons plugin for SPIP before 3.5.0 contains a missing authorization flaw in crayons_store.php that allows unauthenticated attackers to modify arbitrary objects, leading to remote code execution.