First published: Sat Jan 14 2017(Updated: )
comment.php in Serendipity through 2.0.5 allows CSRF in deleting any comments.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Serendipity (S9Y) Freetag Event | <=2.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-5475 has a medium severity due to the potential for CSRF attacks that can lead to unauthorized comment deletion.
To resolve CVE-2017-5475, upgrade to a version of Serendipity later than 2.0.5 that addresses the CSRF vulnerability.
CVE-2017-5475 affects Serendipity versions up to and including 2.0.5.
CVE-2017-5475 is a Cross-Site Request Forgery (CSRF) vulnerability.
Yes, CVE-2017-5475 can lead to data loss by allowing attackers to delete comments without authorization.