Cross-Site Request Forgery Flaw in Serendipity by s9y
CVE-2017-5476

8.8HIGH

Key Information:

Vendor

S9y

Vendor
CVE Published:
14 January 2017

What is CVE-2017-5476?

The Serendipity content management system through version 2.0.5 contains a Cross-Site Request Forgery (CSRF) vulnerability that enables attackers to manipulate the installation of plugins. This flaw can allow unauthorized users to install event or sidebar plugins without proper authentication, potentially compromising the integrity and security of the affected installations.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.