CVE-2010-1647
MediaWiki 1.15-1.15.3 and 1.16 beta 1-2 - Cross-Site Scripting via CSS Strings
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in MediaWiki 1.15 before 1.15.4 and 1.16 before 1.16 beta 3 allows remote attackers to inject arbitrary web script or HTML via crafted Cascading Style Sheets (CSS) strings that are processed as script by Internet Explorer.
References (4)
Core 4
Core References
Issue Tracking x_refsource_confirm
https://bugzilla.wikimedia.org/show_bug.cgi?id=23687
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2010-July/043856.html
Various Sources mailing-list
x_refsource_mlist
http://lists.wikimedia.org/pipermail/mediawiki-announce/2010-May/000091.html
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2010-July/043803.html
Scores
EPSS
0.0025
EPSS Percentile
48.1%
Details
CWE
CWE-79
Status
published
Products (5)
mediawiki/mediawiki
1.15.0 (2 CPE variants)
mediawiki/mediawiki
1.15.1
mediawiki/mediawiki
1.15.2
mediawiki/mediawiki
1.15.3
mediawiki/mediawiki
1.16.0 (3 CPE variants)
Published
Jun 08, 2010
Tracked Since
Feb 18, 2026