CVE-2012-2331
Cross-site scripting (XSS) vulnerability in serendipity/serendipity_admin_image_selector.php in Serendipity before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via the serendipity[textarea] parameter. NOTE: this issue might be resultant from cross-site request forgery (CSRF).
- Affected products
- Serendipity
- s9y Serendipity
- ≤ 1.6, 0.3, 0.4, 0.7, 0.7.1, 0.8, 0.8.1, 0.8.2, 0.8.3, 0.8.4, 0.8.5, 0.9, 0.9.1, 1.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.1, 1.1.1, 1.1.2, 1.1.3, 1.1.4, 1.2, 1.2.1, 1.3, 1.3.1, 1.4, 1.4.1, 1.5.1, 1.5.2, 1.5.3, 1.5.4, 1.5.5, 1.6.1
- Fix
- Available
- CVSS 2.0
- 4.3 MEDIUM
- EPSS
- 4.7% (91th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2012-08-13
CVE-2012-2331 at NVD
4 known exploits for CVE-2012-2331
Proof-of-concept code and exploit modules indexed by Sploitus