First published: Sat Jan 14 2017(Updated: )
Serendipity through 2.0.5 allows CSRF for the installation of an event plugin or a sidebar plugin.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Serendipity (S9Y) Freetag Event | <=2.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-5476 has a moderate severity level, primarily due to its potential for CSRF attacks.
To fix CVE-2017-5476, update your Serendipity installation to a version later than 2.0.5 which contains security enhancements.
CVE-2017-5476 is a Cross-Site Request Forgery (CSRF) vulnerability that affects the installation of plugins.
Users of Serendipity version 2.0.5 and earlier are vulnerable to CVE-2017-5476.
Yes, CVE-2017-5476 can allow an attacker to install malicious plugins on a vulnerable Serendipity site.