Description
Serendipity before 2.1.5 has XSS via EXIF data that is mishandled in the templates/2k11/admin/media_choose.tpl Editor Preview feature or the templates/2k11/admin/media_items.tpl Media Library feature.
Remediation
References
Related Vulnerabilities
MySQL CVE-2015-0382 Vulnerability (CVE-2015-0382)
e107 Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2018-11127)
MyBB CVE-2008-3070 Vulnerability (CVE-2008-3070)
Magento Cryptographic Issues Vulnerability (CVE-2019-7855)
WordPress Plugin WordLift-AI powered SEO-Schema Cross-Site Scripting (3.37.1)