CVE-2012-1582: XSS
Cross-site scripting (XSS) vulnerability in the wikitext parser in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 allows remote attackers to inject arbitrary web script or HTML via a crafted page with "forged strip item markers," as demonstrated using the CharInsert extension.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1582?
CVE-2012-1582 is considered to be of medium severity due to its ability to allow cross-site scripting attacks.
How do I fix CVE-2012-1582?
To fix CVE-2012-1582, upgrade to MediaWiki versions 1.17.3 or 1.18.2 or later.
What types of attacks can CVE-2012-1582 facilitate?
CVE-2012-1582 can facilitate cross-site scripting attacks, allowing attackers to inject arbitrary web scripts or HTML.
Which versions of MediaWiki are affected by CVE-2012-1582?
CVE-2012-1582 affects MediaWiki versions 1.17.x before 1.17.3 and 1.18.x before 1.18.2.
What is the impact of CVE-2012-1582 on users?
The impact of CVE-2012-1582 can lead to user session hijacking, site defacement, or data theft through malicious scripts.