CVE-2011-0003Improper Input Validation in Mediawiki

Severity
5.8MEDIUMNVD
EPSS
0.9%
top 23.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 11
Latest updateMay 3

Description

MediaWiki before 1.16.1, when user or site JavaScript or CSS is enabled, allows remote attackers to conduct clickjacking attacks via unspecified vectors.

CVSS vector

AV:N/AC:M/C:P/I:P/A:NExploitability: 8.6 | Impact: 4.9

Affected Packages3 packages

debiandebian/mediawiki< mediawiki 1:1.15.5-2 (bookworm)
Debianmediawiki/mediawiki< 1:1.15.5-2+3
NVDmediawiki/mediawiki1.16.0+110

Patches

🔴Vulnerability Details

2
GHSA
GHSA-w85r-wgrm-jwhr: MediaWiki before 12022-05-03
OSV
CVE-2011-0003: MediaWiki before 12011-01-11

📋Vendor Advisories

1
Debian
CVE-2011-0003: mediawiki - MediaWiki before 1.16.1, when user or site JavaScript or CSS is enabled, allows ...2011

💬Community

3
Bugzilla
CVE-2011-0003 mediawiki: clickjacking vulnerability2011-01-04
Bugzilla
CVE-2011-0003 mediawiki: clickjacking vulnerability [epel-5]2011-01-04
Bugzilla
CVE-2011-0003 mediawiki: clickjacking vulnerability [fedora-all]2011-01-04
CVE-2011-0003 — Improper Input Validation in Mediawiki | cvebase