CVE-2015-2934: XSS
MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 does not properly handle when the Zend interpreter xmlparse function does not expand entities, which allows remote attackers to inject arbitrary web script or HTML via a crafted SVG file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2934?
CVE-2015-2934 has a high severity rating due to its potential for remote code execution through crafted SVG files.
How do I fix CVE-2015-2934?
To mitigate CVE-2015-2934, upgrade MediaWiki to version 1.19.24 or later, 1.23.9 or later, or 1.24.2 or later.
Which versions of MediaWiki are affected by CVE-2015-2934?
CVE-2015-2934 affects MediaWiki versions before 1.19.24, 1.23.9, and 1.24.2.
What type of vulnerability is CVE-2015-2934?
CVE-2015-2934 is a security vulnerability that enables remote attackers to inject arbitrary web scripts or HTML.
Can CVE-2015-2934 be exploited without user interaction?
Yes, CVE-2015-2934 can be exploited without user interaction through a specially crafted SVG file.