CVE-2017-8101

NONE EPSS 44.6%
Published Apr 24, 20179y ago ยท Modified Jun 17, 20262w ago
Find Similar
Published Apr 24, 2017 9y ago
Last Modified Jun 17, 2026 2w ago

Description

There is CSRF in Serendipity 2.0.5, allowing attackers to install any themes via a GET request.

Threat Intelligence

EPSS Exploit Probability
44.6% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-352 Cross-Site Request Forgery (CSRF) Authentication

Affected Products 1

VendorProductVersionRange
s9yserendipity2.0.5any

References 2

  • seclists.org http://seclists.org/fulldisclosure/2017/Apr/52
    Mailing ListPatchThird Party Advisory
  • github.com https://github.com/s9y/Serendipity/issues/452
    Issue TrackingPatchThird Party Advisory

Remediation

  • seclists.org http://seclists.org/fulldisclosure/2017/Apr/52
    Mailing ListPatchThird Party Advisory
  • github.com https://github.com/s9y/Serendipity/issues/452
    Issue TrackingPatchThird Party Advisory