First published: Wed Jan 22 2020(Updated: )
A Cross-site Scripting (XSS) vulnerability exists in the Serendipity freetag plugin before 3.30 in the tagcloud parameter to plugins/serendipity_event_freetag/tagcloud.swf.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Serendipity (S9Y) Freetag Event | <3.30 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2011-3610.
The severity of CVE-2011-3610 is medium with a CVSS score of 6.1.
The Serendipity freetag plugin before version 3.30 is affected by CVE-2011-3610.
The CWE number for CVE-2011-3610 is CWE-79.
The XSS vulnerability in CVE-2011-3610 can be exploited through the tagcloud parameter in the Serendipity freetag plugin's tagcloud.swf file.