CVE-2015-6734: XSS
Cross-site scripting (XSS) vulnerability in contrib/cssgen.php in the GeSHi, as used in the SyntaxHighlightGeSHi extension and MediaWiki before 1.23.10, 1.24.x before 1.24.3, and 1.25.x before 1.25.2, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-6734?
CVE-2015-6734 is a high-severity cross-site scripting (XSS) vulnerability that can allow remote attackers to inject arbitrary web scripts or HTML.
How do I fix CVE-2015-6734?
To fix CVE-2015-6734, upgrade to MediaWiki version 1.23.10, 1.24.3, or 1.25.2 or later.
Which versions of MediaWiki are affected by CVE-2015-6734?
CVE-2015-6734 affects MediaWiki versions before 1.23.10, 1.24.x before 1.24.3, and 1.25.x before 1.25.2.
Can CVE-2015-6734 be exploited remotely?
Yes, CVE-2015-6734 can be exploited remotely by attackers to inject web scripts through unspecified vectors.
What components are involved in the vulnerability CVE-2015-6734?
The vulnerability CVE-2015-6734 involves the contrib/cssgen.php in the GeSHi, used within the SyntaxHighlight_GeSHi extension of MediaWiki.