GHSA-xcqg-793j-q344LowCVSS 4.3

Serendipity before 2.6.1 contains an open redirect vulnerability in exit.php that allows...

Published
July 31, 2026
Last Modified
July 31, 2026

🔗 CVE IDs covered (1)

📋 Description

Serendipity before 2.6.1 contains an open redirect vulnerability in exit.php that allows unauthenticated attackers to redirect users to arbitrary external sites by supplying a malicious Base64-encoded url parameter when the Track Exits plugin is configured with commentredirection set to s9y. Attackers can craft trusted-looking URLs leveraging the legitimate blog domain to conduct phishing, deliver malware, or bypass URL reputation filters.

🔗 References (4)