First published: Mon Nov 25 2013(Updated: )
Cross-site scripting (XSS) vulnerability in the ZeroRatedMobileAccess extension for MediaWiki 1.19.x before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 allows remote attackers to inject arbitrary web script or HTML via the "to" parameter to index.php.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
MediaWiki | =1.19.0 | |
MediaWiki | =1.19.1 | |
MediaWiki | =1.19.2 | |
MediaWiki | =1.19.3 | |
MediaWiki | =1.19.4 | |
MediaWiki | =1.19.5 | |
MediaWiki | =1.19.6 | |
MediaWiki | =1.19.7 | |
MediaWiki | =1.19.8 | |
MediaWiki | =1.20 | |
MediaWiki | =1.20.1 | |
MediaWiki | =1.20.2 | |
MediaWiki | =1.20.3 | |
MediaWiki | =1.20.4 | |
MediaWiki | =1.20.5 | |
MediaWiki | =1.20.6 | |
MediaWiki | =1.20.7 | |
MediaWiki | =1.21 | |
MediaWiki | =1.21.1 | |
MediaWiki | =1.21.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4573 has a medium severity rating due to its cross-site scripting vulnerability.
To fix CVE-2013-4573, upgrade to MediaWiki version 1.19.9, 1.20.8, or 1.21.3 or later.
CVE-2013-4573 affects users running specific older versions of the ZeroRatedMobileAccess extension for MediaWiki.
CVE-2013-4573 is a cross-site scripting (XSS) vulnerability.
Attackers can inject arbitrary web scripts or HTML through the 'to' parameter in index.php, compromising user data.