CVE-2013-1951
published 2019-10-31CVE-2013-1951: A cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.5 and 1.20.x before 1.20.4 and allows remote attackers to inject arbitrary web script or…
PriorityP425medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
1.64%
73.9th percentile
A cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.5 and 1.20.x before 1.20.4 and allows remote attackers to inject arbitrary web script or HTML via Lua function names.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | mediawiki | < mediawiki 1:1.19.5-1 (bookworm) | mediawiki 1:1.19.5-1 (bookworm) |
| ikimedia_foundation | mediawiki | — | — |
| mediawiki | mediawiki | < 1.19.5 | 1.19.5 |
| mediawiki | mediawiki | >= 0 < 1:1.19.5-1 | 1:1.19.5-1 |
| mediawiki | mediawiki | >= 0 < 1:1.19.5-1 | 1:1.19.5-1 |
| mediawiki | mediawiki | >= 0 < 1:1.19.5-1 | 1:1.19.5-1 |
| mediawiki | mediawiki | >= 0 < 1:1.19.5-1 | 1:1.19.5-1 |
| mediawiki | mediawiki | >= 1.20.0 < 1.20.4 | 1.20.4 |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vendor_debian6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6f76-xp7g-326v: A cross-site scripting (XSS) vulnerability in MediaWiki before 1
ghsa_unreviewed·2022-05-05
CVE-2013-1951 [MEDIUM] GHSA-6f76-xp7g-326v: A cross-site scripting (XSS) vulnerability in MediaWiki before 1
A cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.5 and 1.20.x before 1.20.4 and allows remote attackers to inject arbitrary web script or HTML via Lua function names.
OSV
CVE-2013-1951: A cross-site scripting (XSS) vulnerability in MediaWiki before 1
osv·2019-10-31·CVSS 6.1
CVE-2013-1951 [MEDIUM] CVE-2013-1951: A cross-site scripting (XSS) vulnerability in MediaWiki before 1
A cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.5 and 1.20.x before 1.20.4 and allows remote attackers to inject arbitrary web script or HTML via Lua function names.
Debian
CVE-2013-1951: mediawiki - A cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.5 and 1.20.x...
vendor_debian·2013·CVSS 6.1
CVE-2013-1951 [MEDIUM] CVE-2013-1951: mediawiki - A cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.5 and 1.20.x...
A cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.5 and 1.20.x before 1.20.4 and allows remote attackers to inject arbitrary web script or HTML via Lua function names.
Scope: local
bookworm: resolved (fixed in 1:1.19.5-1)
bullseye: resolved (fixed in 1:1.19.5-1)
forky: resolved (fixed in 1:1.19.5-1)
sid: resolved (fixed in 1:1.19.5-1)
trixie: resolved (fixed in 1:1.19.5-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-1951 mediawiki various flaws [epel-5]
bugzilla·2013-04-18·CVSS 6.1
CVE-2013-1951 [MEDIUM] CVE-2013-1951 mediawiki various flaws [epel-5]
CVE-2013-1951 mediawiki various flaws [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-5 tracking bug for mediawiki: see blocks bug lis
Bugzilla
CVE-2013-1951 mediawiki116 various flaws [epel-all]
bugzilla·2013-04-18·CVSS 6.1
CVE-2013-1951 [MEDIUM] CVE-2013-1951 mediawiki116 various flaws [epel-all]
CVE-2013-1951 mediawiki116 various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects multiple support
Bugzilla
CVE-2013-1951 mediawiki: security releases 1.20.4 and 1.19.5
bugzilla·2013-04-18·CVSS 6.1
CVE-2013-1951 [MEDIUM] CVE-2013-1951 mediawiki: security releases 1.20.4 and 1.19.5
CVE-2013-1951 mediawiki: security releases 1.20.4 and 1.19.5
Three flaws were corrected in the recently-released MediaWiki 1.20.4 and 1.19.5 releases:
* An internal review discovered that specially crafted Lua function names could lead to XSS [1]
* Daniel Franke reported that during SVG parsing, MediaWiki failed to prevent XML external entity (XXE) processing. This could lead to local file disclosure, or potentially remote command execution in environments that have enabled expect:// handling. [2]
* Internal review also discovered that Special:Import, and Extension:RSS failed to prevent XML external entity (XXE) processing. [3]
CVE-2013-1951 was assigned to the first issue (the XSS), the other two do not have CVEs assigned as per a discussion on oss-sec [4].
[1] https://bugzilla.wiki
Bugzilla
CVE-2013-1951 mediawiki: security releases 1.20.4 and 1.19.5 [fedora-all]
bugzilla·2013-04-18·CVSS 6.1
CVE-2013-1951 [MEDIUM] CVE-2013-1951 mediawiki: security releases 1.20.4 and 1.19.5 [fedora-all]
CVE-2013-1951 mediawiki: security releases 1.20.4 and 1.19.5 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects
Bugzilla
CVE-2013-1951 mediawiki: security releases 1.20.4 and 1.19.5 [epel-6]
bugzilla·2013-04-18·CVSS 6.1
CVE-2013-1951 [MEDIUM] CVE-2013-1951 mediawiki: security releases 1.20.4 and 1.19.5 [epel-6]
CVE-2013-1951 mediawiki: security releases 1.20.4 and 1.19.5 [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-6 tracking bug for mediaw
http://lists.fedoraproject.org/pipermail/package-announce/2013-April/104022.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-April/104027.htmlhttp://security.gentoo.org/glsa/glsa-201310-21.xmlhttp://www.openwall.com/lists/oss-security/2013/04/16/12http://www.securityfocus.com/bid/59077https://bugs.gentoo.org/show_bug.cgi?id=CVE-2013-1951https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-1951https://phabricator.wikimedia.org/T48084https://security-tracker.debian.org/tracker/CVE-2013-1951http://lists.fedoraproject.org/pipermail/package-announce/2013-April/104022.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-April/104027.htmlhttp://security.gentoo.org/glsa/glsa-201310-21.xmlhttp://www.openwall.com/lists/oss-security/2013/04/16/12http://www.securityfocus.com/bid/59077https://bugs.gentoo.org/show_bug.cgi?id=CVE-2013-1951https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-1951https://phabricator.wikimedia.org/T48084https://security-tracker.debian.org/tracker/CVE-2013-1951
2019-10-31
Published