CVE-2014-2242

MediaWiki <1.19.12, 1.20.x, 1.21.x <1.21.6, 1.22.x <1.22.3 - XSS

Title source: llm

Description

includes/upload/UploadBase.php in MediaWiki before 1.19.12, 1.20.x and 1.21.x before 1.21.6, and 1.22.x before 1.22.3 does not prevent use of invalid namespaces in SVG files, which allows remote attackers to conduct cross-site scripting (XSS) attacks via an SVG upload, as demonstrated by use of a W3C XHTML namespace in conjunction with an IFRAME element.

Scores

EPSS 0.0050
EPSS Percentile 65.7%

Details

CWE
CWE-79
Status published
Products (50)
mediawiki/mediawiki < 1.19.11
mediawiki/mediawiki
mediawiki/mediawiki
mediawiki/mediawiki
mediawiki/mediawiki
mediawiki/mediawiki
mediawiki/mediawiki
mediawiki/mediawiki
mediawiki/mediawiki
mediawiki/mediawiki
... and 40 more
Published Mar 02, 2014
Tracked Since Feb 18, 2026