CVE-2014-5242: XSS
Cross-site scripting (XSS) vulnerability in mediawiki.page.image.pagination.js in MediaWiki 1.22.x before 1.22.9 and 1.23.x before 1.23.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving the multipageimagenavbox class in conjunction with an action=raw value.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-5242?
CVE-2014-5242 is classified as a high severity vulnerability due to its potential to allow remote attackers to execute arbitrary scripts.
How do I fix CVE-2014-5242?
To fix CVE-2014-5242, upgrade your MediaWiki installation to version 1.22.9 or 1.23.2 or later.
Which versions of MediaWiki are affected by CVE-2014-5242?
CVE-2014-5242 affects MediaWiki versions 1.22.0 through 1.22.8 and 1.23.0 through 1.23.1.
What type of vulnerability is CVE-2014-5242?
CVE-2014-5242 is a cross-site scripting (XSS) vulnerability.
Can CVE-2014-5242 be exploited remotely?
Yes, CVE-2014-5242 can be exploited remotely by attackers through specific vectors.