CVE-2015-2931: XSS
Incomplete blacklist vulnerability in includes/upload/UploadBase.php in MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to inject arbitrary web script or HTML via an application/xml MIME type for a nested SVG with a data: URI.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2931?
CVE-2015-2931 is classified as a medium severity vulnerability.
How do I fix CVE-2015-2931?
To mitigate CVE-2015-2931, upgrade your MediaWiki installation to version 1.19.24 or later, or 1.23.9 and later, or 1.24.2 and later.
What does CVE-2015-2931 affect?
CVE-2015-2931 affects MediaWiki versions prior to 1.19.24, all of 1.20.x, and several versions of 1.21.x through 1.24.x.
What type of attack does CVE-2015-2931 enable?
CVE-2015-2931 allows remote attackers to inject arbitrary web scripts or HTML via an application/xml MIME type for a nested SVG with a data URI.
Is there a workaround for CVE-2015-2931?
The recommended workaround for CVE-2015-2931 is to apply the patches provided by the MediaWiki community or to upgrade to the latest version.