PT-2007-7247 · Serendipity · Serendipity Mycalendar Plugin

Hanno Böck

·

Publicado

2007-12-17

·

Atualizado

2008-09-05

·

CVE-2007-6390

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Serendipity mycalendar plugin versions prior to 0.13
Description A cross-site request forgery (CSRF) issue allows remote attackers to perform actions as blog administrators. This can be leveraged to conduct cross-site scripting (XSS) attacks on the blog page.
Recommendations For versions prior to 0.13, update to version 0.13 or later to resolve the issue. As a temporary workaround, consider restricting access to the mycalendar plugin until a patch is applied.

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-6390

Produtos afetados

Serendipity Mycalendar Plugin