First published: Sun Sep 09 2012(Updated: )
Cross-site scripting (XSS) vulnerability in the wikitext parser in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 allows remote attackers to inject arbitrary web script or HTML via a crafted page with "forged strip item markers," as demonstrated using the CharInsert extension.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
MediaWiki MediaWiki | =1.17 | |
MediaWiki MediaWiki | =1.17-beta_1 | |
MediaWiki MediaWiki | =1.17.0 | |
MediaWiki MediaWiki | =1.17.0-rc1 | |
MediaWiki MediaWiki | =1.17.1 | |
MediaWiki MediaWiki | =1.17.2 | |
MediaWiki MediaWiki | =1.18 | |
MediaWiki MediaWiki | =1.18-beta_1 | |
MediaWiki MediaWiki | =1.18.0 | |
MediaWiki MediaWiki | =1.18.0-rc1 | |
MediaWiki MediaWiki | =1.18.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.