Description
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.6.11, 1.12.x before 1.12.2, and 1.13.x before 1.13.3, when Internet Explorer is used and uploads are enabled, or an SVG scripting browser is used and SVG uploads are enabled, allows remote authenticated users to inject arbitrary web script or HTML by editing a wiki page.
References (8)
Core 8
Core References
Vendor Advisory vendor-advisory
x_refsource_fedora
https://www.redhat.com/archives/fedora-package-announce/2008-December/msg01309.html
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2009/dsa-1901
Patch, Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/33133
Mailing List vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html
Patch, Vendor Advisory mailing-list
x_refsource_mlist
http://lists.wikimedia.org/pipermail/mediawiki-announce/2008-December/000080.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/32844
Vendor Advisory vendor-advisory
x_refsource_fedora
https://www.redhat.com/archives/fedora-package-announce/2008-December/msg01256.html
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/33349
Scores
EPSS
0.0035
EPSS Percentile
57.8%
Details
CWE
CWE-79
Status
published
Products (6)
mediawiki/mediawiki
1.6.11
mediawiki/mediawiki
1.12.0
mediawiki/mediawiki
1.12.1
mediawiki/mediawiki
1.13.0
mediawiki/mediawiki
1.13.1
mediawiki/mediawiki
1.13.2
Published
Dec 19, 2008
Tracked Since
Feb 18, 2026