MEDIUM
SQL injection vulnerability in the serendipity_checkCommentToken function in include/functions_comments.inc.php in Serendipity before 2.0.2, when "Use Tokens for Comment Moderation" is enabled, allows remote administrators to execute arbitrary SQL commands via the serendipity[id] parameter to serendipity_admin.php
Published Sep 15, 2015
6.0
MEDIUMCVSS 2.0
EPSS 1.25%
Description
Affected products
Remediation
Metrics
References (5)
Change history (0)
No recorded changes yet.