CVE-2012-1582Cross-site Scripting in Mediawiki

Severity
4.3MEDIUMNVD
EPSS
0.6%
top 29.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 9
Latest updateMay 17

Description

Cross-site scripting (XSS) vulnerability in the wikitext parser in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 allows remote attackers to inject arbitrary web script or HTML via a crafted page with "forged strip item markers," as demonstrated using the CharInsert extension.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

debiandebian/mediawiki< mediawiki 1:1.15.5-9 (bookworm)
Debianmediawiki/mediawiki< 1:1.15.5-9+3
NVDmediawiki/mediawiki7 versions+6

🔴Vulnerability Details

2
GHSA
GHSA-jqh5-w95m-3mpg: Cross-site scripting (XSS) vulnerability in the wikitext parser in MediaWiki 12022-05-17
OSV
CVE-2012-1582: Cross-site scripting (XSS) vulnerability in the wikitext parser in MediaWiki 12012-09-09

📋Vendor Advisories

1
Debian
CVE-2012-1582: mediawiki - Cross-site scripting (XSS) vulnerability in the wikitext parser in MediaWiki 1.1...2012

💬Community

1
Bugzilla
CVE-2013-1582 wireshark: Infinite loop / crash in the CLNP dissector (wnpa-sec-2013-02, bug 7871)2013-01-31
CVE-2012-1582 — Cross-site Scripting in Mediawiki | cvebase