CVE-2019-11870

Serendipity before 2.1.5 has XSS via EXIF data that is mishandled in the templates/2k11/admin/media_choose.tpl Editor Preview feature or the templates/2k11/admin/media_items.tpl Media Library feature.
References
Configurations

Configuration 1

cpe:2.3:a:s9y:serendipity:*:*:*:*:*:*:*:*

Information

Published : 2019-05-09 11:29

Updated : 2019-05-10 01:23


NVD link : CVE-2019-11870

Mitre link : CVE-2019-11870

Products Affected
CWE