CVE-2008-0124
S9Y Serendipity - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in Serendipity (S9Y) before 1.3-beta1 allows remote authenticated users to inject arbitrary web script or HTML via (1) the "Real name" field in Personal Settings, which is presented to readers of articles; or (2) a file upload, as demonstrated by a .htm, .html, or .js file.
References (9)
Scores
EPSS
0.0065
EPSS Percentile
70.5%
Classification
CWE
CWE-79
Status
draft
Affected Products (34)
s9y/serendipity
s9y/serendipity
s9y/serendipity
s9y/serendipity
s9y/serendipity
s9y/serendipity
s9y/serendipity
s9y/serendipity
s9y/serendipity
s9y/serendipity
s9y/serendipity
s9y/serendipity
s9y/serendipity
s9y/serendipity
s9y/serendipity
... and 19 more
Timeline
Published
Feb 28, 2008
Tracked Since
Feb 18, 2026