CVE-2014-9477: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Listings extension for MediaWiki allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) url parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9477?
The severity of CVE-2014-9477 is classified as medium due to its potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2014-9477?
To fix CVE-2014-9477, upgrade your MediaWiki installation to a version higher than 1.24.0 where these vulnerabilities are patched.
What types of vulnerabilities does CVE-2014-9477 include?
CVE-2014-9477 includes multiple cross-site scripting (XSS) vulnerabilities in the Listings extension for MediaWiki.
Which versions of MediaWiki are affected by CVE-2014-9477?
CVE-2014-9477 affects MediaWiki versions 1.19.22 and earlier, as well as specific versions from 1.20 to 1.23.7.
What can attackers do with CVE-2014-9477?
Attackers exploiting CVE-2014-9477 can inject arbitrary web scripts or HTML, potentially compromising user sessions or manipulating website content.