CVE-2014-9476: Medium severity MediaWiki MediaWiki vulnerability
MediaWiki 1.2x before 1.22.15, 1.23.x before 1.23.8, and 1.24.x before 1.24.1 allows remote attackers to bypass CORS restrictions in $wgCrossSiteAJAXdomains via a domain that has a partial match to an allowed origin, as demonstrated by "http://en.wikipedia.org.evilsite.example/."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9476?
CVE-2014-9476 is considered a medium severity vulnerability as it allows remote attackers to bypass CORS restrictions.
How do I fix CVE-2014-9476?
To fix CVE-2014-9476, upgrade MediaWiki to version 1.22.15 or later, or to version 1.23.8 or later, or to version 1.24.1 or later.
What types of applications are affected by CVE-2014-9476?
CVE-2014-9476 affects various versions of the MediaWiki software prior to the patched releases.
Can CVE-2014-9476 lead to data breaches?
Yes, CVE-2014-9476 can potentially lead to data breaches by allowing unauthorized access to resources across domains.
What are the symptoms of exploitation of CVE-2014-9476?
Exploitation of CVE-2014-9476 may result in unexpected behavior of applications that rely on CORS for security, including unauthorized API access.