CVE-2016-6334
MEDIUMMediaWiki <1.23.15, <1.26.x-<1.26.4, <1.27.x-<1.27.1 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in the Parser::replaceInternalLinks2 method in MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving replacement of percent encoding in unclosed internal links.
References (4)
Scores
CVSS v3
6.1
EPSS
0.0022
EPSS Percentile
44.4%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Classification
CWE
CWE-79
Status
published
Affected Products (8)
mediawiki/mediawiki
< 1.23.14
mediawiki/mediawiki
mediawiki/mediawiki
mediawiki/mediawiki
mediawiki/mediawiki
mediawiki/mediawiki
mediawiki/mediawiki
n/a/n/a
Timeline
Published
Apr 20, 2017
Tracked Since
Feb 18, 2026