Description
Serendipity before 2.1.5 has XSS via EXIF data that is mishandled in the templates/2k11/admin/media_choose.tpl Editor Preview feature or the templates/2k11/admin/media_items.tpl Media Library feature.
Remediation
References
Related Vulnerabilities
WordPress Plugin Simple Video Embedder Cross-Site Scripting (2.2)
WordPress Plugin WooCommerce Cart Expiration PHP Object Injection (0.1.0)
Nginx Out-of-bounds Read Vulnerability (CVE-2023-27727)
WordPress Plugin Multiple Roles Cross-Site Request Forgery (1.3.1)
Oracle Database Server CVE-2014-6467 Vulnerability (CVE-2014-6467)