Serendipity Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2011-4090 - Vulnerability Database

Serendipity Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2011-4090

Medium
Reference: CVE-2011-4090
Title: Serendipity Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

Serendipity before 1.6 has an XSS issue in the karma plugin which may allow privilege escalation.