CVE-2013-4305: XSS
Published Oct 11, 2013
·Updated
Cross-site scripting (XSS) vulnerability in contrib/example.php in the SyntaxHighlight GeSHi extension for MediaWiki, possibly as downloaded before September 2013, allows remote attackers to inject arbitrary web script or HTML via the PATHINFO.
Affected Software
3 affected components
MediaWiki MediaWiki=1.19.7
MediaWiki MediaWiki=1.20.6
MediaWiki MediaWiki=1.21.1
Remediation
Patch Available
Patch Available
Event History
Oct 11, 2013
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-4305?
CVE-2013-4305 is classified as a high severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2013-4305?
To fix CVE-2013-4305, upgrade to MediaWiki version 1.19.8, 1.20.7, or 1.21.2 or later.
3
What systems are affected by CVE-2013-4305?
CVE-2013-4305 affects MediaWiki versions 1.19.7, 1.20.6, and 1.21.1.
4
What type of vulnerability is CVE-2013-4305?
CVE-2013-4305 is a cross-site scripting (XSS) vulnerability.
5
Can CVE-2013-4305 be exploited remotely?
Yes, CVE-2013-4305 can be exploited by remote attackers to inject arbitrary web script or HTML.