CVE-2013-4305
MediaWiki SyntaxHighlight GeSHi Extension - Cross-Site Scripting via PATH_INFO
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in contrib/example.php in the SyntaxHighlight GeSHi extension for MediaWiki, possibly as downloaded before September 2013, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
References (5)
Core 5
Core References
Patch mailing-list
x_refsource_mlist
http://seclists.org/oss-sec/2013/q3/553
Exploit, Patch x_refsource_confirm
https://bugzilla.wikimedia.org/show_bug.cgi?id=49070
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/86890
Various Sources mailing-list
x_refsource_mlist
http://lists.wikimedia.org/pipermail/mediawiki-announce/2013-September/000133.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/96909
Scores
EPSS
0.0019
EPSS Percentile
40.0%
Details
CWE
CWE-79
Status
published
Products (3)
mediawiki/mediawiki
1.19.7
mediawiki/mediawiki
1.20.6
mediawiki/mediawiki
1.21.1
Published
Oct 11, 2013
Tracked Since
Feb 18, 2026