CVE-2011-0003

MediaWiki <1.16.1 - CSRF

Title source: llm
STIX 2.1

Description

MediaWiki before 1.16.1, when user or site JavaScript or CSS is enabled, allows remote attackers to conduct clickjacking attacks via unspecified vectors.

References (11)

Core 11
Core References
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/01/04/12
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0017
Issue Tracking x_refsource_confirm
https://bugzilla.wikimedia.org/show_bug.cgi?id=26561
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/70272
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/059235.html
Patch, Vendor Advisory mailing-list x_refsource_mlist
http://lists.wikimedia.org/pipermail/mediawiki-announce/2011-January/000093.html
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/01/04/6
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/42810
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058910.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/64476
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/059232.html

Scores

EPSS 0.0093
EPSS Percentile 76.3%

Details

CWE
CWE-20
Status published
Products (42)
mediawiki/mediawiki 1.1.0
mediawiki/mediawiki 1.2.0
mediawiki/mediawiki 1.2.1
mediawiki/mediawiki 1.2.2
mediawiki/mediawiki 1.2.3
mediawiki/mediawiki 1.2.4
mediawiki/mediawiki 1.2.5
mediawiki/mediawiki 1.2.6
mediawiki/mediawiki 1.3
mediawiki/mediawiki 1.3.0
... and 32 more
Published Jan 11, 2011
Tracked Since Feb 18, 2026