CVE-2017-5476: CSRF
Published Jan 14, 2017
·Updated
Serendipity through 2.0.5 allows CSRF for the installation of an event plugin or a sidebar plugin.
Affected Software
1 affected component
S9Y serendipity<=2.0.5
Event History
Jan 14, 2017
CVE Published
via MITRE·06:56 AM
Data Sourced
via MITRE·06:56 AM
Description
Data Sourced
via NVD·07:59 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-5476?
CVE-2017-5476 has a moderate severity level, primarily due to its potential for CSRF attacks.
2
How do I fix CVE-2017-5476?
To fix CVE-2017-5476, update your Serendipity installation to a version later than 2.0.5 which contains security enhancements.
3
What type of vulnerability is CVE-2017-5476?
CVE-2017-5476 is a Cross-Site Request Forgery (CSRF) vulnerability that affects the installation of plugins.
4
Who is affected by CVE-2017-5476?
Users of Serendipity version 2.0.5 and earlier are vulnerable to CVE-2017-5476.
5
Can CVE-2017-5476 lead to unauthorized access?
Yes, CVE-2017-5476 can allow an attacker to install malicious plugins on a vulnerable Serendipity site.