CVE-2015-2939

MediaWiki Scribunto - Cross-Site Scripting via Lua Error Backtrace

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in the Scribunto extension for MediaWiki allows remote attackers to inject arbitrary web script or HTML via a function name, which is not properly handled in a Lua error backtrace.

References (7)

Core 7
Core References
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201510-05
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2015:200
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/73477
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/04/07/3
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/04/01/1
Patch, Vendor Advisory mailing-list x_refsource_mlist
https://lists.wikimedia.org/pipermail/mediawiki-announce/2015-March/000175.html
Issue Tracking x_refsource_confirm
https://phabricator.wikimedia.org/T85113

Scores

EPSS 0.0041
EPSS Percentile 61.3%

Details

CWE
CWE-79
Status published
Products (1)
mediawiki/scribunto
Published Apr 13, 2015
Tracked Since Feb 18, 2026