First published: Tue Nov 05 2019(Updated: )
Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code in the image manager.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/dotlrn | ||
debian/openacs | ||
debian/serendipity | ||
Serendipity (S9Y) Freetag Event | <1.5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1134 is considered a medium severity vulnerability due to its potential for remote code execution through cross-site scripting.
CVE-2011-1134 allows remote attackers to execute arbitrary code in the image manager of affected Serendipity packages.
To fix CVE-2011-1134, users should upgrade to the latest version of Serendipity, which is 1.5.5 or later.
CVE-2011-1134 affects Serendipity versions prior to 1.5.5, as well as potentially other related Debian packages like dotlrn and openacs.
There is no separate patch for CVE-2011-1134; upgrading to version 1.5.5 or later is the recommended remediation.