CVE-2012-4378Cross-site Scripting in Mediawiki

Severity
6.1MEDIUMNVD
EPSS
0.5%
top 33.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 26
Latest updateMay 17

Description

Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki before 1.18.5 and 1.19.x before 1.19.2, when unspecified JavaScript gadgets are used, allow remote attackers to inject arbitrary web script or HTML via the userlang parameter to w/index.php.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages3 packages

debiandebian/mediawiki< mediawiki 1:1.19.2-1 (bookworm)
Debianmediawiki/mediawiki< 1:1.19.2-1+3
NVDmediawiki/mediawiki1.18.4+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-9mqw-wh74-5cm9: Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki before 12022-05-17
OSV
CVE-2012-4378: Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki before 12017-10-26

📋Vendor Advisories

1
Debian
CVE-2012-4378: mediawiki - Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki before 1.18.5 a...2012

💬Community

2
Bugzilla
CVE-2012-4377 CVE-2012-4378 CVE-2012-4379 CVE-2012-4380 CVE-2012-4381 mediawiki various flaws [fedora-all]2012-08-31
Bugzilla
CVE-2012-4378 mediawiki: Multiple DOM-based XSS flaws due improper filtering of uselang parameter2012-08-31
CVE-2012-4378 — Cross-site Scripting in Mediawiki | cvebase