CVE-2012-4377: XSS
A stored cross-site scripting (XSS) flaw was found in the way MediaWiki, a wiki engine, sanitized comments when a File::link tag to an non-existent image was rendered. A remote attacker could provide a specially-crafted URL that, when visited would lead to arbitrary HTML or web script injection.
References: [1] http://www.gossamer-threads.com/lists/wiki/mediawiki/295767
Upstream bug: [2] https://bugzilla.wikimedia.org/showbug.cgi?id=39700
Upstream patch against the 1.19 version: [3] https://bugzilla.wikimedia.org/showbug.cgi?id=39700#c11
Upstream patch against the 1.18 version: [4] https://bugzilla.wikimedia.org/showbug.cgi?id=39700#c12
Other sources
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.18.5 and 1.19.x before 1.19.2 allows remote attackers to inject arbitrary web script or HTML via a File: link to a nonexistent image.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4377?
CVE-2012-4377 is classified as a medium severity vulnerability affecting multiple versions of MediaWiki.
How do I fix CVE-2012-4377?
To fix CVE-2012-4377, upgrade MediaWiki to version 1.18.5, 1.19.2, or a later version.
What versions of MediaWiki are affected by CVE-2012-4377?
CVE-2012-4377 affects MediaWiki versions earlier than 1.18.5 and 1.19.x before 1.19.2.
Can CVE-2012-4377 be exploited remotely?
Yes, CVE-2012-4377 can be exploited remotely by attackers to inject arbitrary web scripts or HTML.
What types of attacks are possible due to CVE-2012-4377?
CVE-2012-4377 allows for cross-site scripting (XSS) attacks, potentially compromising user data and site integrity.