Description
Serendipity before 2.1.5 has XSS via EXIF data that is mishandled in the templates/2k11/admin/media_choose.tpl Editor Preview feature or the templates/2k11/admin/media_items.tpl Media Library feature.
Remediation
References
Related Vulnerabilities
WordPress Plugin yolink Search for WordPress Cross-Site Scripting (2.5)
WordPress Plugin Filtre de Surveillance Gouvernemental Cross-Site Scripting (1.1)
MySQL CVE-2022-21264 Vulnerability (CVE-2022-21264)
WordPress Plugin Protected Posts Logout Button Security Bypass (1.4.5)
Jetty Uncontrolled Resource Consumption Vulnerability (CVE-2021-28165)