CVE-2019-15124: XSS
Published Mar 19, 2020
·Updated
In the MobileFrontend extension for MediaWiki, XSS exists within the edit summary field of the watchlist feed. This affects REL131, REL132, and REL133.
Affected Software
3 affected components
MediaWiki Mobilefrontend Mediawiki=1.31.0
MediaWiki Mobilefrontend Mediawiki=1.32.0
MediaWiki Mobilefrontend Mediawiki=1.33.0
Event History
Mar 19, 2020
CVE Published
via MITRE·06:09 PM
Data Sourced
via MITRE·06:09 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-15124?
CVE-2019-15124 has been classified as a moderate severity vulnerability due to its potential impact on user security.
2
How do I fix CVE-2019-15124?
To fix CVE-2019-15124, upgrade the MobileFrontend extension to a version later than 1.33.0.
3
What versions of MobileFrontend are affected by CVE-2019-15124?
CVE-2019-15124 affects MobileFrontend versions 1.31.0, 1.32.0, and 1.33.0.
4
What type of vulnerability is CVE-2019-15124?
CVE-2019-15124 is an XSS (Cross-Site Scripting) vulnerability.
5
Is there a workaround for CVE-2019-15124?
There are no official workarounds for CVE-2019-15124 other than upgrading to a patched version.