CVE-2016-10737: XSS
Published Jan 16, 2019
·Updated
Serendipity 2.0.4 has XSS via the serendipityadmin.php serendipity[body] parameter.
Affected Software
1 affected component
S9Y serendipity=2.0.4
Event History
Jan 16, 2019
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10737?
CVE-2016-10737 is classified as a medium severity vulnerability due to its potential for exploitation via XSS.
2
How do I fix CVE-2016-10737?
To fix CVE-2016-10737, upgrade to a later version of Serendipity that addresses the XSS vulnerability.
3
What is the impact of CVE-2016-10737?
The impact of CVE-2016-10737 is that it allows attackers to inject malicious scripts through the serendipity[body] parameter.
4
Is CVE-2016-10737 present in versions of Serendipity later than 2.0.4?
CVE-2016-10737 is specifically present in Serendipity version 2.0.4; later versions should not be affected.
5
What kind of attacks can exploit CVE-2016-10737?
CVE-2016-10737 can be exploited for cross-site scripting (XSS) attacks, potentially allowing an attacker to hijack user sessions.