First published: Thu Oct 26 2017(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki before 1.18.5 and 1.19.x before 1.19.2, when unspecified JavaScript gadgets are used, allow remote attackers to inject arbitrary web script or HTML via the userlang parameter to w/index.php.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/mediawiki | 1:1.31.16-1+deb10u2 1:1.31.16-1+deb10u6 1:1.35.11-1~deb11u1 1:1.35.13-1~deb11u1 1:1.39.4-1~deb12u1 1:1.39.5-1~deb12u1 1:1.39.5-1 | |
MediaWiki | <=1.18.4 | |
MediaWiki | =1.19.0 | |
MediaWiki | =1.19.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4378 is classified as a moderate severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2012-4378, update MediaWiki to version 1.18.5 or later, or 1.19.2 or later.
CVE-2012-4378 allows attackers to perform cross-site scripting (XSS) attacks by injecting arbitrary web scripts or HTML.
CVE-2012-4378 affects MediaWiki versions prior to 1.18.5 and the 1.19.x versions prior to 1.19.2.
No, CVE-2012-4378 can be exploited by unauthenticated remote attackers.