CVE-2013-2031: XSS
MediaWiki before 1.19.6 and 1.20.x before 1.20.5 allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by a CDATA section containing valid UTF-7 encoded sequences in a SVG file, which is then incorrectly interpreted as UTF-8 by Chrome and Firefox.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2031?
CVE-2013-2031 is classified as a high severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2013-2031?
To fix CVE-2013-2031, upgrade MediaWiki to version 1.19.6 or 1.20.5 or later.
Which versions of MediaWiki are affected by CVE-2013-2031?
CVE-2013-2031 affects MediaWiki versions prior to 1.19.6 and all 1.20.x versions before 1.20.5.
What are the potential impacts of CVE-2013-2031?
The potential impacts of CVE-2013-2031 include unauthorized script execution in a user's browser leading to data theft or session hijacking.
How can I determine if my MediaWiki installation is vulnerable to CVE-2013-2031?
To determine if your MediaWiki installation is vulnerable, check the version against the affected versions listed for CVE-2013-2031.