Cross-Site Request Forgery in Serendipity 2.0.5 by S9Y
CVE-2017-8101

8.8HIGH

Key Information:

Vendor

S9y

Vendor
CVE Published:
24 April 2017

What is CVE-2017-8101?

A vulnerability exists in Serendipity version 2.0.5 that allows attackers to exploit Cross-Site Request Forgery (CSRF) to send unauthorized GET requests. These requests can enable the installation of arbitrary themes without user consent, leading to potential manipulation or malicious use of the affected site. This flaw poses a significant risk to the security and integrity of user data, demanding immediate mitigation and preventive measures.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.