Description
Multiple cross-site scripting (XSS) vulnerabilities in Serendipity before 2.0.5 allow remote authenticated users to inject arbitrary web script or HTML via a category or directory name.
Remediation
References
Related Vulnerabilities
WordPress Plugin Site Kit by Google Security Bypass (1.7.1)
Ruby Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-1005)
PHP Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2011-3379)
Plupload Cross-site Scripting (XSS) Vulnerability (CVE-2016-4566)
Chamilo Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2022-27427)