Description
Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code in the image manager.
Remediation
References
Related Vulnerabilities
WordPress 3.7.x Cross-Site Request Forgery (3.7 - 3.7.28)
WordPress Plugin InfiniteWP Client Security Bypass (1.9.4.4)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2013-1817)
Jenkins Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-2609)