PT-2025-50531 · Unknown · Serendipity

Published

2025-12-10

·

Updated

2025-12-11

·

CVE-2024-58282

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Serendipity version 2.5.0
Description An authenticated administrator can upload malicious PHP files through the media upload functionality, leading to remote code execution. An attacker can create a PHP shell with a command execution form, enabling arbitrary system command execution on the web server. The vulnerability exists due to improper handling of file uploads.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-58282

Affected Products

Serendipity