CVE-2013-4308: XSS
Cross-site scripting (XSS) vulnerability in pages/TalkpageHistoryView.php in the LiquidThreads (LQT) extension 2.x and possibly 3.x for MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 allows remote attackers to inject arbitrary web script or HTML via a thread subject.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4308?
CVE-2013-4308 is classified as a medium severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2013-4308?
To fix CVE-2013-4308, update the LiquidThreads extension to version 2.2 or later and ensure that you are using a patched version of MediaWiki.
What types of software are affected by CVE-2013-4308?
CVE-2013-4308 affects LiquidThreads extensions 2.x and possibly 3.x, and specific versions of MediaWiki 1.19.x, 1.20.x, and 1.21.x.
Can CVE-2013-4308 be exploited remotely?
Yes, CVE-2013-4308 allows remote attackers to inject arbitrary web scripts or HTML via a thread subject.
What systems are vulnerable to CVE-2013-4308?
Systems running vulnerable versions of the LiquidThreads extension and the specified versions of MediaWiki are at risk from CVE-2013-4308.