Description
Serendipity before 2.1.5 has XSS via EXIF data that is mishandled in the templates/2k11/admin/media_choose.tpl Editor Preview feature or the templates/2k11/admin/media_items.tpl Media Library feature.
Remediation
References
Related Vulnerabilities
WordPress 4.8.x Arbitrary File Deletion Vulnerability (4.8 - 4.8.6)
MediaWiki Improper Privilege Management Vulnerability (CVE-2021-44857)
PHP Cryptographic Issues Vulnerability (CVE-2015-8867)
Jboss EAP CVE-2021-32029 Vulnerability (CVE-2021-32029)
Apache HTTP Server CVE-2010-0425 Vulnerability (CVE-2010-0425)