CVE-2015-2933: XSS
Cross-site scripting (XSS) vulnerability in the Html class in MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to inject arbitrary web script or HTML via a LanguageConverter substitution string when using a language variant.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2933?
CVE-2015-2933 is rated as moderate severity due to its potential to allow cross-site scripting attacks.
How do I fix CVE-2015-2933?
To fix CVE-2015-2933, upgrade MediaWiki to version 1.19.24, 1.23.9, or 1.24.2 or later to ensure the vulnerability is patched.
What software versions are affected by CVE-2015-2933?
CVE-2015-2933 affects MediaWiki versions prior to 1.19.24, 1.23.9, and 1.24.2.
What type of attack does CVE-2015-2933 facilitate?
CVE-2015-2933 facilitates cross-site scripting (XSS) attacks through arbitrary web script or HTML injection.
Who can exploit CVE-2015-2933?
Remote attackers can exploit CVE-2015-2933 to inject malicious scripts if the affected MediaWiki versions are not updated.