First published: Tue Oct 04 2005(Updated: )
Cross-site request forgery (CSRF) vulnerability in Serendipity 0.8.4 and earlier allows remote attackers to perform unauthorized actions as a logged in user via a link or IMG tag to serendipity_admin.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Serendipity (S9Y) Freetag Event | <=0.8.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3129 is classified as a medium severity vulnerability due to its potential to allow unauthorized actions by attackers.
To fix CVE-2005-3129, upgrade to Serendipity version 0.8.5 or later which addresses the CSRF vulnerability.
CVE-2005-3129 is a Cross-site Request Forgery (CSRF) vulnerability affecting Serendipity software.
CVE-2005-3129 affects Serendipity versions 0.8.4 and earlier.
The potential impact of CVE-2005-3129 includes unauthorized actions performed by an attacker while impersonating a logged-in user.