CVE-2014-9507: XSS
MediaWiki 1.21.x, 1.22.x before 1.22.14, and 1.23.x before 1.23.7, when $wgContentHandlerUseDB is enabled, allows remote attackers to conduct cross-site scripting (XSS) attacks by setting the content model for a revision to JS.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9507?
CVE-2014-9507 is considered a critical vulnerability that allows for cross-site scripting (XSS) attacks.
How do I fix CVE-2014-9507?
To fix CVE-2014-9507, update your MediaWiki installation to version 1.22.14 or later, or 1.23.7 or later.
What versions of MediaWiki are affected by CVE-2014-9507?
CVE-2014-9507 affects MediaWiki versions 1.21.x, 1.22.x before 1.22.14, and 1.23.x before 1.23.7.
Can CVE-2014-9507 lead to data breach?
Yes, CVE-2014-9507 can potentially lead to data breaches by allowing attackers to execute malicious scripts in the context of the user's session.
What is cross-site scripting in the context of CVE-2014-9507?
In the context of CVE-2014-9507, cross-site scripting (XSS) refers to the injection of malicious scripts into web pages viewed by other users.