CVE-2017-0372

CRITICAL

MediaWiki < 1.23.16, 1.27.3, 1.28.2 - Parameter Injection in SyntaxHighlight Extension

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2017-0372. Includes Metasploit module exploits/multi/http/mediawiki_syntaxhighlight.

AI-analyzed exploit summary This Metasploit module exploits an option injection vulnerability in the MediaWiki SyntaxHighlight extension to create and execute a PHP file in the document root. It leverages the 'cssfile' and 'classprefix' parameters to inject malicious PHP code, achieving remote code execution.

Description

Parameters injection in the SyntaxHighlight extension of Mediawiki before 1.23.16, 1.27.3 and 1.28.2 might result in multiple vulnerabilities.

Exploits (1)

metasploit WORKING POC GOOD
rubypocphp
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/mediawiki_syntaxhighlight.rb

This Metasploit module exploits an option injection vulnerability in the MediaWiki SyntaxHighlight extension to create and execute a PHP file in the document root. It leverages the 'cssfile' and 'classprefix' parameters to inject malicious PHP code, achieving remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: MediaWiki with SyntaxHighlight extension 2.0 (affects MediaWiki 1.27.x and 1.28.x)
Auth required
Prerequisites: MediaWiki installation with vulnerable SyntaxHighlight extension · Network access to the target · Optional authentication credentials if the wiki is private
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Patch, Release Notes, Vendor Advisory mailing-list x_refsource_mlist
https://lists.wikimedia.org/pipermail/mediawiki-announce/2017-April/000207.html
Patch, Release Notes, Vendor Advisory mailing-list x_refsource_mlist
https://lists.wikimedia.org/pipermail/mediawiki-announce/2017-April/000209.html
Third Party Advisory x_refsource_misc
https://bugs.debian.org/861585
Exploit, Third Party Advisory x_refsource_confirm
https://phabricator.wikimedia.org/T158689
Issue Tracking, Third Party Advisory x_refsource_confirm
https://security-tracker.debian.org/tracker/CVE-2017-0372

Scores

CVSS v3 9.8
EPSS 0.1165
EPSS Percentile 95.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-74
Status published
Products (8)
debian/debian_linux 7.0
debian/debian_linux 9.0
mediawiki/mediawiki 1.27.0
mediawiki/mediawiki 1.27.1
mediawiki/mediawiki 1.27.2
mediawiki/mediawiki 1.28.0
mediawiki/mediawiki 1.28.1
mediawiki/mediawiki < 1.23.15
Published Apr 13, 2018
Tracked Since Feb 18, 2026