Description
Cross-site request forgery (CSRF) vulnerability in Serendipity 0.8.4 and earlier allows remote attackers to perform unauthorized actions as a logged in user via a link or IMG tag to serendipity_admin.php.
Remediation
References
Related Vulnerabilities
WordPress Plugin Qiniu Cloudtuchuang Cross-Site Scripting (1.8)
WordPress Plugin BuddyPress Multiple Cross-Site Request Forgery Vulnerabilities (2.8.1)
Squid Permissions, Privileges, and Access Controls Vulnerability (CVE-2015-5400)
WordPress 4.8.x Arbitrary File Deletion Vulnerability (4.8 - 4.8.6)