CVE-2007-6390: XSS
Published Dec 17, 2007
·Updated
Cross-site request forgery (CSRF) vulnerability in the mycalendar plugin before 0.13 for Serendipity allows remote attackers to perform actions as blog administrators, which can be leveraged to conduct cross-site scripting (XSS) attacks on the blog page.
Affected Software
1 affected component
serendipity Serendipity<=0.12
Event History
Dec 17, 2007
CVE Published
06:46 PM
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-6390?
CVE-2007-6390 has a medium severity level due to its potential for enabling unauthorized actions as blog administrators.
2
How do I fix CVE-2007-6390?
To fix CVE-2007-6390, upgrade the mycalendar plugin to version 0.13 or later.
3
What actions can be exploited through CVE-2007-6390?
CVE-2007-6390 allows attackers to perform unauthorized actions as blog administrators, which can lead to further vulnerabilities.
4
Is CVE-2007-6390 related to XSS attacks?
Yes, CVE-2007-6390 can be leveraged to conduct cross-site scripting (XSS) attacks on the blog page.
5
Which versions of Serendipity are affected by CVE-2007-6390?
CVE-2007-6390 affects Serendipity versions prior to 0.13.