CVE-2007-4828Cross-site Scripting in Mediawiki

Severity
4.3MEDIUMNVD
EPSS
0.5%
top 32.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 12
Latest updateMay 1

Description

Cross-site scripting (XSS) vulnerability in the API pretty-printing mode in MediaWiki 1.8.0 through 1.8.4, 1.9.0 through 1.9.3, 1.10.0 through 1.10.1, and the 1.11 development versions before 1.11.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

debiandebian/mediawiki< mediawiki 1.10.2-1 (bookworm)
Debianmediawiki/mediawiki< 1.10.2-1+3
NVDmediawiki/mediawiki16 versions+15

Patches

🔴Vulnerability Details

3
GHSA
GHSA-wwwr-px3v-p7c5: Cross-site scripting (XSS) vulnerability in the BotQuery extension in MediaWiki 12022-05-01
GHSA
GHSA-p3p4-rqcf-gp8r: Cross-site scripting (XSS) vulnerability in the API pretty-printing mode in MediaWiki 12022-05-01
OSV
CVE-2007-4828: Cross-site scripting (XSS) vulnerability in the API pretty-printing mode in MediaWiki 12007-09-12

📋Vendor Advisories

1
Debian
CVE-2007-4828: mediawiki - Cross-site scripting (XSS) vulnerability in the API pretty-printing mode in Medi...2007

💬Community

1
Bugzilla
CVE-2007-4828 mediawiki cross-site scripting vulnerability2007-09-12
CVE-2007-4828 — Cross-site Scripting in Mediawiki | cvebase