Loading HuntDB...

GHSA-p3xc-xr5c-cc37

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

Stored XSS in Serendipity v2.1-rc1 allows an attacker to steal an admin's cookie and other information by composing a new entry as an editor user. This is related to lack of the serendipity_event_xsstrust plugin and a set_config error in that plugin.

Related CVEs

Key Information

GHSA ID
GHSA-p3xc-xr5c-cc37
Published
May 17, 2022 2:47 AM
Last Modified
May 17, 2022 2:47 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: August 30, 2025 6:32 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.