CVE-2014-7295: XSS
The (1) Special:Preferences and (2) Special:UserLogin pages in MediaWiki before 1.19.20, 1.22.x before 1.22.12 and 1.23.x before 1.23.5 allows remote authenticated users to conduct cross-site scripting (XSS) attacks or have unspecified other impact via crafted CSS, as demonstrated by modifying MediaWiki:Common.css.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-7295?
CVE-2014-7295 is classified as having a medium severity due to its potential for cross-site scripting attacks.
How do I fix CVE-2014-7295?
To mitigate CVE-2014-7295, upgrade MediaWiki to version 1.19.20, 1.22.12, or 1.23.5 or later.
What are the attack vectors for CVE-2014-7295?
Attack vectors for CVE-2014-7295 include the Special:Preferences and Special:UserLogin pages where crafted CSS can be exploited.
Who is affected by CVE-2014-7295?
CVE-2014-7295 affects all remote authenticated users of MediaWiki versions prior to 1.19.20, 1.22.12, and 1.23.5.
What types of impact can CVE-2014-7295 have?
CVE-2014-7295 can lead to cross-site scripting (XSS) attacks, allowing attackers to execute malicious scripts in users' browsers.