Unrated severityNVD Advisory· Published Aug 9, 2007· Updated Apr 23, 2026
CVE-2007-4282
CVE-2007-4282
Description
The "Extended properties for entries" (entryproperties) plugin in serendipity_event_entryproperties.php in Serendipity 1.1.3 allows remote authenticated users to bypass password protection and "deliver custom entryproperties settings to the Serendipity Frontend" via a certain request that modifies the password being checked.
Affected products
1- cpe:2.3:a:serendipity:serendipity:1.1.3:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- sourceforge.net/forum/forum.phpnvdPatch
- secunia.com/advisories/26347nvdVendor Advisory
- blog.drinsama.de/erich/en/security/2007080801-security-issue-in-serendipity.htmlnvd
- blog.s9y.org/archives/178-Serendipity-1.1.4-released%2C-security-bug-in-entryproperties-plugin.htmlnvd
- osvdb.org/36534nvd
- sourceforge.net/project/shownotes.phpnvd
- www.securityfocus.com/bid/25235nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/35868nvd
News mentions
0No linked articles in our index yet.