CVE-2014-9475

MediaWiki <1.19.23, 1.2x<1.22.15, 1.23.x<1.23.8, 1.24.x<1.24.1 - XSS

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in thumb.php in MediaWiki before 1.19.23, 1.2x before 1.22.15, 1.23.x before 1.23.8, and 1.24.x before 1.24.1 allows remote authenticated users to inject arbitrary web script or HTML via a wikitext message.

References (5)

Core 5
Core References
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2014/dsa-3110
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/01/03/13
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2014/12/21/2
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2015:006

Scores

EPSS 0.0016
EPSS Percentile 36.8%

Details

CWE
CWE-79
Status published
Products (46)
mediawiki/mediawiki 1.20
mediawiki/mediawiki 1.20.1
mediawiki/mediawiki 1.20.2
mediawiki/mediawiki 1.20.3
mediawiki/mediawiki 1.20.4
mediawiki/mediawiki 1.20.5
mediawiki/mediawiki 1.20.6
mediawiki/mediawiki 1.20.7
mediawiki/mediawiki 1.20.8
mediawiki/mediawiki 1.21
... and 36 more
Published Jan 16, 2015
Tracked Since Feb 18, 2026