First published: Mon May 12 2014(Updated: )
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to inject arbitrary web script or HTML via crafted XSL in an SVG file.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wikimedia MediaWiki | =1.22.0 | |
Wikimedia MediaWiki | =1.21 | |
Wikimedia MediaWiki | =1.21.1 | |
Wikimedia MediaWiki | =1.21.2 | |
Wikimedia MediaWiki | =1.21.3 | |
Wikimedia MediaWiki | <=1.19.9 | |
Wikimedia MediaWiki | =1.19 | |
Wikimedia MediaWiki | =1.19-beta_1 | |
Wikimedia MediaWiki | =1.19-beta_2 | |
Wikimedia MediaWiki | =1.19.0 | |
Wikimedia MediaWiki | =1.19.1 | |
Wikimedia MediaWiki | =1.19.2 | |
Wikimedia MediaWiki | =1.19.3 | |
Wikimedia MediaWiki | =1.19.4 | |
Wikimedia MediaWiki | =1.19.5 | |
Wikimedia MediaWiki | =1.19.6 | |
Wikimedia MediaWiki | =1.19.7 | |
Wikimedia MediaWiki | =1.19.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-6452 has a medium severity rating allowing for cross-site scripting attacks.
To fix CVE-2013-6452, upgrade MediaWiki to version 1.19.10 or later, 1.21.4 or later, or 1.22.1 or later.
CVE-2013-6452 affects users of MediaWiki versions prior to 1.19.10, 1.21.4, and 1.22.1.
CVE-2013-6452 can facilitate cross-site scripting (XSS) attacks allowing arbitrary web scripts to be injected.
CVE-2013-6452 is present in MediaWiki versions 1.19.x before 1.19.10, 1.21.x before 1.21.4, and 1.22.x before 1.22.1.