CVE-2009-4589 — Cross-site Scripting in Mediawiki
Severity
4.3MEDIUMNVD
EPSS
0.4%
top 40.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 7
Latest updateMay 2
Description
Cross-site scripting (XSS) vulnerability in the Special:Block implementation in the getContribsLink function in SpecialBlockip.php in MediaWiki 1.14.0 and 1.15.0 allows remote attackers to inject arbitrary web script or HTML via the ip parameter.
CVSS vector
AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9
Affected Packages4 packages
Patches
🔴Vulnerability Details
2GHSA▶
GHSA-7wv2-pcxg-363g: Cross-site scripting (XSS) vulnerability in the Special:Block implementation in the getContribsLink function in SpecialBlockip↗2022-05-02
OSV▶
CVE-2009-4589: Cross-site scripting (XSS) vulnerability in the Special:Block implementation in the getContribsLink function in SpecialBlockip↗2010-01-07
📋Vendor Advisories
1Debian▶
CVE-2009-4589: mediawiki - Cross-site scripting (XSS) vulnerability in the Special:Block implementation in ...↗2009