CVE-2017-5474: Medium severity S9Y serendipity vulnerability
Published Jan 14, 2017
·Updated
Open redirect vulnerability in comment.php in Serendipity through 2.0.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the HTTP Referer header.
Affected Software
1 affected component
S9Y serendipity<=2.0.5
Remediation
Event History
Jan 14, 2017
CVE Published
via MITRE·06:56 AM
Data Sourced
via MITRE·06:56 AM
Description
Data Sourced
via NVD·07:59 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-5474?
CVE-2017-5474 is considered a high severity vulnerability due to its potential for exploitation in phishing attacks.
2
How do I fix CVE-2017-5474?
To fix CVE-2017-5474, upgrade Serendipity to version 2.0.6 or later.
3
What systems are affected by CVE-2017-5474?
CVE-2017-5474 affects Serendipity versions up to and including 2.0.5.
4
What type of vulnerability is CVE-2017-5474?
CVE-2017-5474 is an open redirect vulnerability.
5
What can attackers do with CVE-2017-5474?
Attackers can exploit CVE-2017-5474 to redirect users to arbitrary websites, enabling phishing attacks.