Serendipity 2.0.2 Cross Site Scripting

2015.10.29
Credit: Joel V
Risk: Low
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-79

#Date: 28/10/2015 #Discovered by: Joel Vadodil Varghese #Type of vulnerability: Stored XSS #Tested on: Windows 8.1 #Product: Serendipity #Version: 2.0.2 #Description: Application is vulnerable to Stored XSS attack. There is a XSS issue in version 2.0.2. and the vulnerable parameters are "Blog name" and "Description". Notified Vendor: September 20, 2015 Response: October 28, 2015 Closure of the security bug: Version 2.0.x Reference: https://github.com/s9y/Serendipity/issues/365 (Vendor Confirmation) Thanks, Joel V


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top