CVE-2017-5609 describes a critical SQL injection vulnerability in Serendipity 2.0.5, specifically within the include/functions_entries.inc.php file. This flaw allows remote authenticated users to execute arbitrary SQL commands by manipulating the 'cat' parameter. With a CVSSv3 score of 8.8 (High), successful exploitation could lead to high confidentiality, integrity, and availability impacts. While no public exploits, Metasploit modules, or Nuclei templates are currently available, and community discussion is minimal, the vulnerability's nature makes it a significant risk if exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0.5CPE matchmatch criteria | cpe:2.3:a:s9y:serendipity:2.0.5:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.