Lucene search

K
cvelistRedhatCVELIST:CVE-2012-2331
HistoryOct 03, 2022 - 4:15 p.m.

CVE-2012-2331

2022-10-0316:15:37
redhat
www.cve.org
2
xss
serendipity
1.6.1
remote attacks
html
csrf

5.7 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

67.9%

Cross-site scripting (XSS) vulnerability in serendipity/serendipity_admin_image_selector.php in Serendipity before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via the serendipity[textarea] parameter. NOTE: this issue might be resultant from cross-site request forgery (CSRF).

5.7 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

67.9%