Medium severity6.1NVD Advisory· Published May 9, 2019· Updated Jun 17, 2026
CVE-2019-11870
CVE-2019-11870
Description
Serendipity before 2.1.5 has XSS via EXIF data that is mishandled in the templates/2k11/admin/media_choose.tpl Editor Preview feature or the templates/2k11/admin/media_items.tpl Media Library feature.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Serendipity/Serendipitydescription
- Range: <2.1.5
Patches
Vulnerability mechanics
References
4- www.openwall.com/lists/oss-security/2019/05/10/1nvdMailing ListThird Party Advisory
- blog.s9y.org/archives/282-Serendipity-2.1.5-released.htmlnvdRelease NotesVendor Advisory
- github.com/s9y/Serendipity/issues/598nvdThird Party Advisory
- www.openwall.com/lists/oss-security/2019/05/03/3nvdMailing ListThird Party Advisory
News mentions
0No linked articles in our index yet.