First published: Wed Sep 11 2013(Updated: )
Cross-site scripting (XSS) vulnerability in pages/TalkpageHistoryView.php in the LiquidThreads (LQT) extension 2.x and possibly 3.x for MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 allows remote attackers to inject arbitrary web script or HTML via a thread subject.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
LiquidThreads | =2.0-alpha | |
LiquidThreads | =2.1-alpha | |
MediaWiki | =1.19 | |
MediaWiki | =1.19-beta_1 | |
MediaWiki | =1.19-beta_2 | |
MediaWiki | =1.19.0 | |
MediaWiki | =1.19.1 | |
MediaWiki | =1.19.2 | |
MediaWiki | =1.19.3 | |
MediaWiki | =1.19.4 | |
MediaWiki | =1.19.5 | |
MediaWiki | =1.19.6 | |
MediaWiki | =1.19.7 | |
MediaWiki | =1.20 | |
MediaWiki | =1.20.1 | |
MediaWiki | =1.20.2 | |
MediaWiki | =1.20.3 | |
MediaWiki | =1.20.4 | |
MediaWiki | =1.20.5 | |
MediaWiki | =1.20.6 | |
MediaWiki | =1.21 | |
MediaWiki | =1.21.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4308 is classified as a medium severity cross-site scripting (XSS) vulnerability.
To fix CVE-2013-4308, update the LiquidThreads extension to version 2.2 or later and ensure that you are using a patched version of MediaWiki.
CVE-2013-4308 affects LiquidThreads extensions 2.x and possibly 3.x, and specific versions of MediaWiki 1.19.x, 1.20.x, and 1.21.x.
Yes, CVE-2013-4308 allows remote attackers to inject arbitrary web scripts or HTML via a thread subject.
Systems running vulnerable versions of the LiquidThreads extension and the specified versions of MediaWiki are at risk from CVE-2013-4308.