First published: Fri Nov 17 2017(Updated: )
Serendipity 2.0.3 is vulnerable to a SQL injection in the blog component resulting in information disclosure
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Serendipity (S9Y) Freetag Event | =2.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-1000129 is classified as high due to the potential for information disclosure.
To fix CVE-2017-1000129, upgrade to Serendipity version 2.0.4 or later.
CVE-2017-1000129 is a SQL injection vulnerability affecting the blog component.
Only Serendipity version 2.0.3 is vulnerable to CVE-2017-1000129.
No specific workaround is advised for CVE-2017-1000129; upgrading is the recommended action.