CVE-2013-4305

MediaWiki SyntaxHighlight GeSHi Extension - Cross-Site Scripting via PATH_INFO

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in contrib/example.php in the SyntaxHighlight GeSHi extension for MediaWiki, possibly as downloaded before September 2013, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

References (5)

Core 5
Core References
Patch mailing-list x_refsource_mlist
http://seclists.org/oss-sec/2013/q3/553
Exploit, Patch x_refsource_confirm
https://bugzilla.wikimedia.org/show_bug.cgi?id=49070
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/86890
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/96909

Scores

EPSS 0.0019
EPSS Percentile 40.0%

Details

CWE
CWE-79
Status published
Products (3)
mediawiki/mediawiki 1.19.7
mediawiki/mediawiki 1.20.6
mediawiki/mediawiki 1.21.1
Published Oct 11, 2013
Tracked Since Feb 18, 2026