Cross-Site Request Forgery Flaw in Serendipity by s9y
CVE-2017-5476
8.8HIGH
What is CVE-2017-5476?
The Serendipity content management system through version 2.0.5 contains a Cross-Site Request Forgery (CSRF) vulnerability that enables attackers to manipulate the installation of plugins. This flaw can allow unauthorized users to install event or sidebar plugins without proper authentication, potentially compromising the integrity and security of the affected installations.
