4.3
CVSSv2

CVE-2019-11870

Published: 09/05/2019 Updated: 10/05/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Serendipity prior to 2.1.5 has XSS via EXIF data that is mishandled in the templates/2k11/admin/media_choose.tpl Editor Preview feature or the templates/2k11/admin/media_items.tpl Media Library feature.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

s9y serendipity

Mailing Lists

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 On Fri, May 03, 2019 at 05:42:18PM +0200, Hanno Böck wrote: MITRE assigned CVE-2019-11870 for this issue - -- Henri Salo -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEE/aVSDznAZReWTkxKJ633pE6qdXQFAlzVOGIACgkQJ633pE6q dXT6lhAArWXR0Lp36yH57N6sgGLLF+gQavAOK+DfGjpOIkGsr9stlFzdfSD5HvSM EASX//8sMenVE ...