CVE-2015-2938: XSS
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to inject arbitrary web script or HTML via a custom JavaScript file, which is not properly handled when previewing the file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2938?
CVE-2015-2938 has a medium severity rating due to its potential to allow remote attackers to execute arbitrary scripts.
How do I fix CVE-2015-2938?
To fix CVE-2015-2938, upgrade MediaWiki to version 1.19.24 or later, or to 1.23.9 or later for the 1.2x series.
What versions of MediaWiki are affected by CVE-2015-2938?
MediaWiki versions prior to 1.19.24, 1.23.9, and 1.24.2 are affected by CVE-2015-2938.
What impact does CVE-2015-2938 have on my website?
CVE-2015-2938 can lead to cross-site scripting (XSS) attacks, which may compromise user data and trust in your website.
Is there a workaround for CVE-2015-2938 if I cannot update MediaWiki?
There are no official workarounds for CVE-2015-2938, so updating to a secure version is strongly advised.