SQL Injection Vulnerability in Serendipity Blog Component by Serendipity Developer
CVE-2017-1000129

7.5HIGH

Key Information:

Vendor

S9y

Vendor
CVE Published:
17 November 2017

What is CVE-2017-1000129?

The Serendipity blog software version 2.0.3 contains a vulnerability in its blog component that allows attackers to execute SQL injection attacks. This weakness can lead to unauthorized access to sensitive information stored in the database, facilitating further exploitation of the application and potential data breaches. Users of this version are strongly advised to upgrade to newer, patched releases to mitigate this risk.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.