Description
Serendipity before 2.1.5 has XSS via EXIF data that is mishandled in the templates/2k11/admin/media_choose.tpl Editor Preview feature or the templates/2k11/admin/media_items.tpl Media Library feature.
Remediation
References
Related Vulnerabilities
MongoDb Out-of-bounds Read Vulnerability (CVE-2017-14227)
WordPress Plugin wp-easybooking Cross-Site Scripting (1.0.3)
Oracle Database Server CVE-2009-1965 Vulnerability (CVE-2009-1965)
Oracle Database Server CVE-2021-2234 Vulnerability (CVE-2021-2234)
WordPress Plugin Image Optimizer, Resizer and CDN-Sirv SQL Injection (1.3.1)