CVE-2017-1000129: SQL Injection
Published Nov 17, 2017
·Updated
Serendipity 2.0.3 is vulnerable to a SQL injection in the blog component resulting in information disclosure
Affected Software
1 affected component
S9Y serendipity=2.0.3
Event History
Nov 17, 2017
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-1000129?
The severity of CVE-2017-1000129 is classified as high due to the potential for information disclosure.
2
How do I fix CVE-2017-1000129?
To fix CVE-2017-1000129, upgrade to Serendipity version 2.0.4 or later.
3
What type of vulnerability is CVE-2017-1000129?
CVE-2017-1000129 is a SQL injection vulnerability affecting the blog component.
4
What versions are affected by CVE-2017-1000129?
Only Serendipity version 2.0.3 is vulnerable to CVE-2017-1000129.
5
Is there a workaround for CVE-2017-1000129?
No specific workaround is advised for CVE-2017-1000129; upgrading is the recommended action.