CVE-2014-9276

MediaWiki <1.19.22, 1.20.x-1.22.x before 1.22.14, 1.23.x before 1.2...

Title source: llm
STIX 2.1

Description

Cross-site request forgery (CSRF) vulnerability in the Special:ExpandedTemplates page in MediaWiki before 1.19.22, 1.20.x through 1.22.x before 1.22.14, and 1.23.x before 1.23.7, when $wgRawHTML is set to true, allows remote attackers to hijack the authentication of users with edit permissions for requests that cross-site scripting (XSS) attacks via the wpInput parameter, which is not properly handled in the preview.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1031301
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2014/12/03/9
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2014/12/04/16
Issue Tracking x_refsource_confirm
https://phabricator.wikimedia.org/T73111
Patch, Vendor Advisory mailing-list x_refsource_mlist
https://lists.wikimedia.org/pipermail/mediawiki-announce/2014-November/000170.html

Scores

EPSS 0.0011
EPSS Percentile 29.5%

Details

CWE
CWE-352
Status published
Products (42)
mediawiki/mediawiki 1.20
mediawiki/mediawiki 1.20.1
mediawiki/mediawiki 1.20.2
mediawiki/mediawiki 1.20.3
mediawiki/mediawiki 1.20.4
mediawiki/mediawiki 1.20.5
mediawiki/mediawiki 1.20.6
mediawiki/mediawiki 1.20.7
mediawiki/mediawiki 1.20.8
mediawiki/mediawiki 1.21
... and 32 more
Published Jan 04, 2015
Tracked Since Feb 18, 2026