VulnerabilityModified
CVE-2017-5474
Open redirect vulnerability in comment.php in Serendipity through 2.0.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the HTTP Referer header.
MEDIUM 6.1EPSS 0.93%
Does this matter?
Lower severity and a low EPSS score (0.93%). Track it; it rarely justifies an emergency change on its own.
Description
Open redirect vulnerability in comment.php in Serendipity through 2.0.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the HTTP Referer header.
- CVSS 3.0
- 6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.93% probability · 59th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-601
- Affected
- s9y/serendipity
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/95652Third Party Advisory, VDB Entry
- https://github.com/s9y/Serendipity/commit/6285933470bab2923e4573b5d54ba9a32629b0cdIssue Tracking, Patch
- http://www.securityfocus.com/bid/95652Third Party Advisory, VDB Entry
- https://github.com/s9y/Serendipity/commit/6285933470bab2923e4573b5d54ba9a32629b0cdIssue Tracking, Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.