First published: Fri Aug 09 2019(Updated: )
In the MobileFrontend extension 1.31 through 1.33 for MediaWiki, XSS exists within the edit summary field in includes/specials/MobileSpecialPageFeed.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MediaWiki MobileFrontend | >=1.31.0<=1.33.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14807 is classified as a moderate severity vulnerability due to its Cross-Site Scripting (XSS) impact.
To fix CVE-2019-14807, upgrade the MobileFrontend extension to version 1.34 or later.
MediaWiki versions 1.31 through 1.33 are affected by CVE-2019-14807.
CVE-2019-14807 could allow attackers to execute arbitrary JavaScript in the context of the user’s browser.
CVE-2019-14807 specifically impacts MediaWiki installations using the MobileFrontend extension.