CVE-2017-5475: CSRF
Published Jan 14, 2017
·Updated
comment.php in Serendipity through 2.0.5 allows CSRF in deleting any comments.
Affected Software
1 affected component
S9Y serendipity<=2.0.5
Event History
Jan 14, 2017
CVE Published
via MITRE·06:56 AM
Data Sourced
via MITRE·06:56 AM
Description
Data Sourced
via NVD·07:59 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-5475?
CVE-2017-5475 has a medium severity due to the potential for CSRF attacks that can lead to unauthorized comment deletion.
2
How do I fix CVE-2017-5475?
To resolve CVE-2017-5475, upgrade to a version of Serendipity later than 2.0.5 that addresses the CSRF vulnerability.
3
What software is affected by CVE-2017-5475?
CVE-2017-5475 affects Serendipity versions up to and including 2.0.5.
4
What type of vulnerability is CVE-2017-5475?
CVE-2017-5475 is a Cross-Site Request Forgery (CSRF) vulnerability.
5
Can CVE-2017-5475 lead to data loss?
Yes, CVE-2017-5475 can lead to data loss by allowing attackers to delete comments without authorization.