CVE-2014-9481: Infoleak
The Scribunto extension for MediaWiki allows remote attackers to obtain the rollback token and possibly other sensitive information via a crafted module, related to unstripping special page HTML.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9481?
CVE-2014-9481 has a moderate severity level due to the potential exposure of sensitive information.
How do I fix CVE-2014-9481?
To fix CVE-2014-9481, you should upgrade MediaWiki to version 1.19.23 or from 1.19.24 to any version newer than 1.22.15.
What versions of MediaWiki are affected by CVE-2014-9481?
CVE-2014-9481 affects MediaWiki versions up to 1.19.23 and between 1.19.24 to 1.22.15, as well as from 1.23.0 to 1.23.8 and from 1.23.9 to 1.24.1.
What types of attacks are possible with CVE-2014-9481?
CVE-2014-9481 allows remote attackers to obtain sensitive information, including the rollback token, via a crafted module.
Is there a workaround for CVE-2014-9481 if I cannot upgrade?
There are no specific workarounds mentioned for CVE-2014-9481, so upgrading is the recommended course of action.