CVE-2013-4301Sensitive Information Exposure in Mediawiki

Severity
5.0MEDIUMNVD
EPSS
0.7%
top 27.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 27
Latest updateMay 17

Description

includes/resourceloader/ResourceLoaderContext.php in MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 allows remote attackers to obtain sensitive information via a "<" (open angle bracket) character in the lang parameter to w/load.php, which reveals the installation path in an error message.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

debiandebian/mediawiki< mediawiki 1:1.19.8+dfsg-1 (bookworm)
Debianmediawiki/mediawiki< 1:1.19.8+dfsg-1+3
NVDmediawiki/mediawiki17 versions+16

Patches

🔴Vulnerability Details

2
GHSA
GHSA-6762-rqcg-h338: includes/resourceloader/ResourceLoaderContext2022-05-17
OSV
CVE-2013-4301: includes/resourceloader/ResourceLoaderContext2013-10-27

📋Vendor Advisories

1
Debian
CVE-2013-4301: mediawiki - includes/resourceloader/ResourceLoaderContext.php in MediaWiki 1.19.x before 1.1...2013

💬Community

1
Bugzilla
CVE-2013-4301 CVE-2013-4302 CVE-2013-4303 mediawiki: security releases 1.21.2, 1.20.7, and 1.19.82013-09-04
CVE-2013-4301 — Sensitive Information Exposure | cvebase