CVE-2012-6453: XSS
Published Dec 31, 2012
·Updated
Cross-site scripting (XSS) vulnerability in the RSS Reader extension before 0.2.6 for MediaWiki allows remote attackers to inject arbitrary web script or HTML via a crafted feed.
Affected Software
6 affected components
MediaWiki Rssreader<=0.2.5
MediaWiki Rssreader=0.2
MediaWiki Rssreader=0.2.1
MediaWiki Rssreader=0.2.2
MediaWiki Rssreader=0.2.3
MediaWiki Rssreader=0.2.4
Event History
Dec 31, 2012
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-6453?
CVE-2012-6453 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2012-6453?
To fix CVE-2012-6453, upgrade the RSS Reader extension to version 0.2.6 or later.
3
What versions of MediaWiki are affected by CVE-2012-6453?
CVE-2012-6453 affects MediaWiki RSS Reader extension versions up to and including 0.2.5.
4
Who can exploit CVE-2012-6453?
Remote attackers can exploit CVE-2012-6453 through crafted feeds to inject arbitrary web script or HTML.
5
What is the impact of CVE-2012-6453?
The impact of CVE-2012-6453 is the potential for users to be subjected to malicious scripts, leading to various security risks.