CVE-2011-0047

MediaWiki < 1.16.2 - Cross-Site Scripting via CSS Comments

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in MediaWiki before 1.16.2 allows remote attackers to inject arbitrary web script or HTML via crafted Cascading Style Sheets (CSS) comments, aka "CSS injection vulnerability."

References (10)

Core 10
Core References
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0273
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/65126
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/059235.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/70770
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058910.html
Issue Tracking x_refsource_confirm
https://bugzilla.wikimedia.org/show_bug.cgi?id=27093
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/46108
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/43142
Patch, Vendor Advisory mailing-list x_refsource_mlist
http://lists.wikimedia.org/pipermail/mediawiki-announce/2011-February/000095.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/059232.html

Scores

EPSS 0.0084
EPSS Percentile 74.9%

Details

CWE
CWE-79
Status published
Products (42)
mediawiki/mediawiki 1.1.0
mediawiki/mediawiki 1.2.0
mediawiki/mediawiki 1.2.1
mediawiki/mediawiki 1.2.2
mediawiki/mediawiki 1.2.3
mediawiki/mediawiki 1.2.4
mediawiki/mediawiki 1.2.5
mediawiki/mediawiki 1.2.6
mediawiki/mediawiki 1.3
mediawiki/mediawiki 1.3.0
... and 32 more
Published Feb 04, 2011
Tracked Since Feb 18, 2026