Description
Serendipity before 2.3.4 on Windows allows remote attackers to execute arbitrary code because the filename of a renamed file may end with a dot. This file may then be renamed to have a .php filename.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP-Live Chat by 3CX Cross-Site Scripting (8.0.17)
WordPress Plugin Accept Signups 'email' Parameter Cross-Site Scripting (0.1)
WordPress Plugin Apptivo eCommerce Multiple Cross-Site Scripting Vulnerabilities (1.1.5)
LimeSurvey Incorrect Default Permissions Vulnerability (CVE-2019-16186)