Serendipity versions >= 2.3.5 and <= 2.6.0 contain a reflected cross-site scripting vulnerability in the search clean-URL route (/search/<term>). In include/functions_routing.inc.php serveSearch(), the sanitisation pipeline runs urldecode() after HTML-encoding, so a single URL-encoded HTML payload survives strip_tags() and htmlspecialchars() and is then decoded back into live HTML in the page. A crafted search link can execute arbitrary JavaScript in the victim's browser.
Fixed in 2.6.1.
Attack Parameters
Impact Assessment
CVSS Vector v4.0
Weakness Type (CWE)
Vulnerable Products 6
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
S9y Serendipity
cpe:2.3:a:s9y:serendipity:2.5.0:-:*:*:*:*:*:*
|
— | — |
|
S9y Serendipity
cpe:2.3:a:s9y:serendipity:2.4.0:-:*:*:*:*:*:*
|
— | — |
|
S9y Serendipity
cpe:2.3:a:s9y:serendipity:2.6.0:beta1:*:*:*:*:*:*
|
— | — |
|
S9y Serendipity
cpe:2.3:a:s9y:serendipity:2.6.0:-:*:*:*:*:*:*
|
— | — |
|
S9y Serendipity
cpe:2.3:a:s9y:serendipity:2.4.0:beta1:*:*:*:*:*:*
|
— | — |
|
S9y Serendipity
cpe:2.3:a:s9y:serendipity:2.3.5:*:*:*:*:*:*:*
|
— | — |