CVE-2012-4378: XSS
Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki before 1.18.5 and 1.19.x before 1.19.2, when unspecified JavaScript gadgets are used, allow remote attackers to inject arbitrary web script or HTML via the userlang parameter to w/index.php.
Other sources
Multiple DOM-based cross-site scripting (XSS) flaws were found in the way MediaWiki, a wiki engine, performed filtering of the uselang parameter. When JavaScript gadgets were used, a remote attacker could provide a specially-crafted URL that, when visited would lead to arbitrary HTML or web script execution.
References: [1] http://www.gossamer-threads.com/lists/wiki/mediawiki/295767
Upstream bug: [2] https://bugzilla.wikimedia.org/showbug.cgi?id=37587
Relevant upstream patch: [3] https://gerrit.wikimedia.org/r/#/c/13336/
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4378?
CVE-2012-4378 is classified as a moderate severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2012-4378?
To fix CVE-2012-4378, update MediaWiki to version 1.18.5 or later, or 1.19.2 or later.
What types of attacks can be performed using CVE-2012-4378?
CVE-2012-4378 allows attackers to perform cross-site scripting (XSS) attacks by injecting arbitrary web scripts or HTML.
Which versions of MediaWiki are affected by CVE-2012-4378?
CVE-2012-4378 affects MediaWiki versions prior to 1.18.5 and the 1.19.x versions prior to 1.19.2.
Is authentication required to exploit CVE-2012-4378?
No, CVE-2012-4378 can be exploited by unauthenticated remote attackers.