CVE-2015-6729: XSS
Cross-site scripting (XSS) vulnerability in thumb.php in MediaWiki before 1.23.10, 1.24.x before 1.24.3, and 1.25.x before 1.25.2 allows remote attackers to inject arbitrary web script or HTML via the rel404 parameter, which is not properly handled in an error page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-6729?
CVE-2015-6729 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2015-6729?
To fix CVE-2015-6729, upgrade MediaWiki to version 1.23.10, 1.24.3, or 1.25.2 or later.
What types of attacks are possible due to CVE-2015-6729?
CVE-2015-6729 allows remote attackers to conduct cross-site scripting attacks, potentially leading to data theft or session hijacking.
Which versions of MediaWiki are affected by CVE-2015-6729?
CVE-2015-6729 affects MediaWiki versions prior to 1.23.10, 1.24.x before 1.24.3, and 1.25.x before 1.25.2.
How can CVE-2015-6729 impact users visiting vulnerable websites?
Users visiting a vulnerable MediaWiki installation could have malicious scripts executed in their browsers, compromising their security and privacy.