vendor:
Serendipity
by:
Mirabbas Agalarov
5.5
CVSS
MEDIUM
Cross-Site Scripting (XSS)
79
CWE
Product Name: Serendipity
Affected Version From: 2.4.2000
Affected Version To: 2.4.2000
Patch Exists: NO
Related CWE:
CPE: a:serendipity:serendipity:2.4.0
Platforms Tested: Linux
2023
Serendipity 2.4.0 – Cross-Site Scripting (XSS)
An attacker who has the authority to create a new entry can execute a stored XSS attack by injecting malicious payload into the application.
Mitigation:
Implement proper input validation and output encoding to prevent XSS attacks.