CVE-2009-4589: XSS
Published Jan 7, 2010
·Updated
Cross-site scripting (XSS) vulnerability in the Special:Block implementation in the getContribsLink function in SpecialBlockip.php in MediaWiki 1.14.0 and 1.15.0 allows remote attackers to inject arbitrary web script or HTML via the ip parameter.
Affected Software
2 affected components
MediaWiki MediaWik=i1.15.0
MediaWiki MediaWiki=1.14.0
Remediation
Patch Available
Patch Available
Event History
Jan 7, 2010
CVE Published
via MITRE·06:13 PM
Data Sourced
via MITRE·06:13 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-4589?
CVE-2009-4589 has a moderate severity level due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2009-4589?
To fix CVE-2009-4589, upgrade MediaWiki to versions 1.15.1 or higher, which address this vulnerability.
3
Who is affected by CVE-2009-4589?
CVE-2009-4589 affects users of MediaWiki versions 1.14.0 and 1.15.0.
4
What type of vulnerability is CVE-2009-4589?
CVE-2009-4589 is a cross-site scripting (XSS) vulnerability that allows remote code injection.
5
Can CVE-2009-4589 lead to data theft?
Yes, CVE-2009-4589 can potentially lead to data theft through unauthorized script execution in a user's browser.