First published: Thu Mar 19 2020(Updated: )
In the MobileFrontend extension for MediaWiki, XSS exists within the edit summary field of the watchlist feed. This affects REL1_31, REL1_32, and REL1_33.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MediaWiki MobileFrontend | =1.31.0 | |
MediaWiki MobileFrontend | =1.32.0 | |
MediaWiki MobileFrontend | =1.33.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-15124 has been classified as a moderate severity vulnerability due to its potential impact on user security.
To fix CVE-2019-15124, upgrade the MobileFrontend extension to a version later than 1.33.0.
CVE-2019-15124 affects MobileFrontend versions 1.31.0, 1.32.0, and 1.33.0.
CVE-2019-15124 is an XSS (Cross-Site Scripting) vulnerability.
There are no official workarounds for CVE-2019-15124 other than upgrading to a patched version.