CVE-2019-14807: XSS
Published Aug 9, 2019
·Updated
In the MobileFrontend extension 1.31 through 1.33 for MediaWiki, XSS exists within the edit summary field in includes/specials/MobileSpecialPageFeed.php.
Affected Software
1 affected component
MediaWiki Mobilefrontend Mediawiki>=1.31.0<=1.33.0
Remediation
Patch Available
Event History
Aug 9, 2019
CVE Published
via MITRE·08:28 PM
Data Sourced
via MITRE·08:28 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-14807?
CVE-2019-14807 is classified as a moderate severity vulnerability due to its Cross-Site Scripting (XSS) impact.
2
How do I fix CVE-2019-14807?
To fix CVE-2019-14807, upgrade the MobileFrontend extension to version 1.34 or later.
3
What versions of MediaWiki are affected by CVE-2019-14807?
MediaWiki versions 1.31 through 1.33 are affected by CVE-2019-14807.
4
What damage can CVE-2019-14807 cause?
CVE-2019-14807 could allow attackers to execute arbitrary JavaScript in the context of the user’s browser.
5
Is CVE-2019-14807 specific to certain configurations of MediaWiki?
CVE-2019-14807 specifically impacts MediaWiki installations using the MobileFrontend extension.