CVE-2010-1916: High severity Xinha WYSIWYG editor vulnerability

Published May 12, 2010
·
Updated

Common Vulnerabilities and Exposures assigned an identifier CVE-2010-1916 to the following vulnerability:

Name: CVE-2010-1916 URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1916 Assigned: 20100511 Reference: MISC: http://www.php-security.org/2010/05/10/mops-2010-019-serendipity-wysiwyg-editor-plugin-configuration-injection-vulnerability/index.html Reference: MISC: http://www.php-security.org/2010/05/10/mops-2010-020-xinha-wysiwyg-plugin-configuration-injection-vulnerability/index.html

The dynamic configuration feature in Xinha WYSIWYG editor 0.96 Beta 2 and earlier, as used in Serendipity 1.5.2 and earlier, allows remote attackers to bypass intended access restrictions and modify the configuration of arbitrary plugins via (1) crafted backendconfigsecretkeylocation and backendconfighash parameters that are used in a SHA1 hash of a shared secret that can be known or externally influenced, which are not properly handled by the "Deprecated config passing" feature; or (2) crafted backenddata and backenddata[keylocation] variables, which are not properly handled by the xinhareadpasseddata function. NOTE: this can be leveraged to upload and possibly execute arbitrary files via config.inc.php in the ImageManager plugin.

The upstream bug report [1] has links to patches to correct this issue.

[1] http://trac.xinha.org/ticket/1518

Affected Software

82 affected components
Xinha WYSIWYG editor=0.9-beta
Xinha WYSIWYG editor=0.91-beta
Xinha WYSIWYG editor=0.92-beta
Xinha WYSIWYG editor=0.93
Xinha WYSIWYG editor=0.94
Xinha WYSIWYG editor=0.95
Xinha WYSIWYG editor=0.96-beta
Xinha WYSIWYG editor=0.96-beta2
S9Y Serendipity=0.3
S9Y Serendipity=0.4
S9Y Serendipity=0.5-pl1
S9Y Serendipity=0.6-pl3
S9Y Serendipity=0.7
S9Y Serendipity=0.7.1
S9Y Serendipity=0.8
S9Y Serendipity=0.8.1
S9Y Serendipity=0.8.2
S9Y Serendipity=0.8.3
S9Y Serendipity=0.8.4
S9Y Serendipity=0.8.5
S9Y Serendipity=0.9
S9Y Serendipity=0.9.1
S9Y Serendipity=1.0
S9Y Serendipity=1.0.1
S9Y Serendipity=1.0.2
S9Y Serendipity=1.0.3
S9Y Serendipity=1.0.4
S9Y Serendipity=1.1
S9Y Serendipity=1.1.1
S9Y Serendipity=1.1.2
S9Y Serendipity=1.1.3
S9Y Serendipity=1.1.4
S9Y Serendipity=1.2
S9Y Serendipity=1.2.1
S9Y Serendipity=1.3
S9Y Serendipity=1.3.1
S9Y Serendipity=1.4
S9Y Serendipity=1.4.1
S9Y Serendipity=1.5
S9Y Serendipity=1.5.1
S9Y Serendipity=1.5.2
All of the following
Any of the following
Xinha WYSIWYG editor=0.9-beta
Xinha WYSIWYG editor=0.91-beta
Xinha WYSIWYG editor=0.92-beta
Xinha WYSIWYG editor=0.93
Xinha WYSIWYG editor=0.94
Xinha WYSIWYG editor=0.95
Xinha WYSIWYG editor=0.96-beta
Xinha WYSIWYG editor=0.96-beta2
Any of the following
S9Y Serendipity=0.3
S9Y Serendipity=0.4
S9Y Serendipity=0.5-pl1
S9Y Serendipity=0.6-pl3
S9Y Serendipity=0.7
S9Y Serendipity=0.7.1
S9Y Serendipity=0.8
S9Y Serendipity=0.8.1
S9Y Serendipity=0.8.2
S9Y Serendipity=0.8.3
S9Y Serendipity=0.8.4
S9Y Serendipity=0.8.5
S9Y Serendipity=0.9
S9Y Serendipity=0.9.1
S9Y Serendipity=1.0
S9Y Serendipity=1.0.1
S9Y Serendipity=1.0.2
S9Y Serendipity=1.0.3
S9Y Serendipity=1.0.4
S9Y Serendipity=1.1
S9Y Serendipity=1.1.1
S9Y Serendipity=1.1.2
S9Y Serendipity=1.1.3
S9Y Serendipity=1.1.4
S9Y Serendipity=1.2
S9Y Serendipity=1.2.1
S9Y Serendipity=1.3
S9Y Serendipity=1.3.1
S9Y Serendipity=1.4
S9Y Serendipity=1.4.1
S9Y Serendipity=1.5
S9Y Serendipity=1.5.1
S9Y Serendipity=1.5.2

Event History

May 12, 2010
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
11:46 AM
DescriptionWeaknessAffected Software
Data Sourced
via NVD·11:46 AM
DescriptionSeverityWeaknessAffected Software
Data Sourced
via Red Hat·08:50 PM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2010-1916?

CVE-2010-1916 has a medium severity rating due to its potential impact on application configuration and access control.

2

How do I fix CVE-2010-1916?

To mitigate CVE-2010-1916, ensure that the plugin configuration settings are secured and review access permissions for files associated with the Xinha WYSIWYG editor.

3

Which versions of software are affected by CVE-2010-1916?

CVE-2010-1916 affects multiple versions of the Xinha WYSIWYG editor ranging from 0.9-beta to 0.96-beta2, as well as various versions of the Serendipity (S9Y) Freetag Event.

4

What type of vulnerability is CVE-2010-1916?

CVE-2010-1916 is classified as a configuration injection vulnerability that can allow unauthorized access to sensitive areas of an application.

5

How can I find out more about CVE-2010-1916?

Further details on CVE-2010-1916 can be found in security advisories and reports related to the affected software versions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203