Description
Serendipity before 2.1.5 has XSS via EXIF data that is mishandled in the templates/2k11/admin/media_choose.tpl Editor Preview feature or the templates/2k11/admin/media_items.tpl Media Library feature.
Remediation
References
Related Vulnerabilities
WordPress Plugin WordPress Automatic SQL Injection (3.92.0)
e107 Other Vulnerability (CVE-2005-2327)
Atlassian Confluence Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-29450)
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-1902)
WordPress Plugin Social Share Buttons-Social Pug Cross-Site Scripting (1.2.5)