PT-2007-7247 · Serendipity · Serendipity Mycalendar Plugin

Hanno Böck

·

Published

2007-12-17

·

Updated

2008-09-05

·

CVE-2007-6390

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Serendipity mycalendar plugin versions prior to 0.13
Description A cross-site request forgery (CSRF) issue allows remote attackers to perform actions as blog administrators. This can be leveraged to conduct cross-site scripting (XSS) attacks on the blog page.
Recommendations For versions prior to 0.13, update to version 0.13 or later to resolve the issue. As a temporary workaround, consider restricting access to the mycalendar plugin until a patch is applied.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-6390

Affected Products

Serendipity Mycalendar Plugin