CVE-2010-1647

MediaWiki 1.15-1.15.3 and 1.16 beta 1-2 - Cross-Site Scripting via CSS Strings

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in MediaWiki 1.15 before 1.15.4 and 1.16 before 1.16 beta 3 allows remote attackers to inject arbitrary web script or HTML via crafted Cascading Style Sheets (CSS) strings that are processed as script by Internet Explorer.

References (4)

Core 4
Core References
Issue Tracking x_refsource_confirm
https://bugzilla.wikimedia.org/show_bug.cgi?id=23687
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2010-July/043856.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2010-July/043803.html

Scores

EPSS 0.0025
EPSS Percentile 48.1%

Details

CWE
CWE-79
Status published
Products (5)
mediawiki/mediawiki 1.15.0 (2 CPE variants)
mediawiki/mediawiki 1.15.1
mediawiki/mediawiki 1.15.2
mediawiki/mediawiki 1.15.3
mediawiki/mediawiki 1.16.0 (3 CPE variants)
Published Jun 08, 2010
Tracked Since Feb 18, 2026