Serendipity Security Advisory - XSS Vulnerability - CVE-2015-8603 Jan 07 2016 04:06PM
Onur Yilmaz (onur netsparker com)
Advisory by Netsparker
Name: XSS Vulnerability in Serendipity
Affected Software : Serendipity
Affected Versions: v2.0.2 and possibly below
Vendor Homepage : http://www.s9y.org
Vulnerability Type : Cross-site Scripting
Severity : Important
Status : Fixed
CVE-ID : CVE-2015-8603
Netsparker Advisory Reference : NS-15-024

By exploiting a Cross-site scripting vulnerability the attacker can
hijack a logged in userâ??s session. This means that the malicious
hacker can change the logged in userâ??s password and invalidate the
session of the victim while the hacker maintains access. As seen from
the XSS example in this article, if a web application is vulnerable to
cross-site scripting and the administratorâ??s session is hijacked, the
malicious hacker exploiting the vulnerability will have full admin
privileges on that web application.

Technical Details
Proof of Concept URL for XSS in Serendipity v2.0.2:


For more information on cross-site scripting vulnerabilities read the
following article on Cross-site Scripting (XSS) -

Advisory Timeline
07/12/2015 - First Contact
17/12/2015 - Vendor Fixed
05/01/2016 - Advisory Released


Credits & Authors
These issues have been discovered by Selçuk Miynat while testing
Netsparker Web Application Security Scanner -

About Netsparker
Netsparker web application security scanners find and report security
flaws and vulnerabilities such as SQL Injection and Cross-site
Scripting (XSS) in all websites and web applications, regardless of
the platform and technology they are built on. Netsparker scanning
engineâ??s unique detection and exploitation techniques allow it to be
dead accurate in reporting vulnerabilities. The Netsparker web
application security scanner is available in two editions; Netsparker
Desktop and Netsparker Cloud. Visit our website
https://www.netsparker.com for more information.

Onur Yılmaz - National General Manager

Netsparker Web Application Security Scanner
T: +90 (0)554 873 0482

[ reply ]


Privacy Statement
Copyright 2010, SecurityFocus