CVE-2009-4589Cross-site Scripting in Mediawiki

Severity
4.3MEDIUMNVD
EPSS
0.4%
top 40.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 7
Latest updateMay 2

Description

Cross-site scripting (XSS) vulnerability in the Special:Block implementation in the getContribsLink function in SpecialBlockip.php in MediaWiki 1.14.0 and 1.15.0 allows remote attackers to inject arbitrary web script or HTML via the ip parameter.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages4 packages

debiandebian/mediawiki< mediawiki 1:1.15.0-1.1 (bookworm)
Debianmediawiki/mediawiki< 1:1.15.0-1.1+3
NVDmediawiki/mediawiki1.15.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-7wv2-pcxg-363g: Cross-site scripting (XSS) vulnerability in the Special:Block implementation in the getContribsLink function in SpecialBlockip2022-05-02
OSV
CVE-2009-4589: Cross-site scripting (XSS) vulnerability in the Special:Block implementation in the getContribsLink function in SpecialBlockip2010-01-07

📋Vendor Advisories

1
Debian
CVE-2009-4589: mediawiki - Cross-site scripting (XSS) vulnerability in the Special:Block implementation in ...2009
CVE-2009-4589 — Cross-site Scripting in Mediawiki | cvebase