PT-2019-6615 · Serendipity · Serendipity
David Vieira-Kurz
·
Published
2019-11-05
·
Updated
2019-11-08
·
CVE-2011-1133
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Serendipity versions prior to 1.5.5
Description
The issue allows remote attackers to execute arbitrary code. This is due to a Cross-Site Scripting (XSS) flaw in Xinha, which is included in the Serendipity package. The vulnerability can be exploited via the
backend.php file in the plugins/ExtendedFileManager directory.Recommendations
For versions prior to 1.5.5, update to version 1.5.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the
backend.php file in the plugins/ExtendedFileManager directory to minimize the risk of exploitation.Fix
RCE
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Serendipity