PT-2026-66760 · Unknown · Serendipity
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Serendipity versions prior to 2.6.1
Description
An open redirect issue exists in the 'exit.php' endpoint. Unauthenticated attackers can redirect users to arbitrary external sites by providing a malicious Base64-encoded
url parameter. This occurs when the Track Exits plugin is configured with the commentredirection setting set to 's9y'. This flaw allows attackers to create URLs that appear trusted by using the legitimate blog domain to perform phishing, deliver malware, or bypass URL reputation filters.Recommendations
Update to version 2.6.1 or later.
As a temporary mitigation, avoid configuring the Track Exits plugin with
commentredirection set to 's9y'.Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Serendipity