CVE-2013-6451
published 2020-01-28CVE-2013-6451: Cross-site scripting (XSS) vulnerability in MediaWiki 1.19.9 before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to inject…
PriorityP423medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
1.08%
61.3th percentile
Cross-site scripting (XSS) vulnerability in MediaWiki 1.19.9 before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to inject arbitrary web script or HTML via unspecified CSS values.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mediawiki | < mediawiki 1:1.19.10+dfsg-1 (bookworm) | mediawiki 1:1.19.10+dfsg-1 (bookworm) |
| mediawiki | mediawiki | >= 0 < 1:1.19.10+dfsg-1 | 1:1.19.10+dfsg-1 |
| mediawiki | mediawiki | >= 0 < 1:1.19.10+dfsg-1 | 1:1.19.10+dfsg-1 |
| mediawiki | mediawiki | >= 0 < 1:1.19.10+dfsg-1 | 1:1.19.10+dfsg-1 |
| mediawiki | mediawiki | >= 0 < 1:1.19.10+dfsg-1 | 1:1.19.10+dfsg-1 |
| mediawiki | mediawiki | >= 1.19.9 < 1.19.10 | 1.19.10 |
| mediawiki | mediawiki | >= 1.20.0 < 1.21.4 | 1.21.4 |
| mediawiki | mediawiki | >= 1.22.0 < 1.22.1 | 1.22.1 |
| wikimedia_foundation | mediawiki | — | — |
| wikimedia_foundation | mediawiki | — | — |
| wikimedia_foundation | mediawiki | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vendor_debian6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2013-6451: mediawiki - Cross-site scripting (XSS) vulnerability in MediaWiki 1.19.9 before 1.19.10, 1.2...
vendor_debian·2013·CVSS 6.1
CVE-2013-6451 [MEDIUM] CVE-2013-6451: mediawiki - Cross-site scripting (XSS) vulnerability in MediaWiki 1.19.9 before 1.19.10, 1.2...
Cross-site scripting (XSS) vulnerability in MediaWiki 1.19.9 before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to inject arbitrary web script or HTML via unspecified CSS values.
Scope: local
bookworm: resolved (fixed in 1:1.19.10+dfsg-1)
bullseye: resolved (fixed in 1:1.19.10+dfsg-1)
forky: resolved (fixed in 1:1.19.10+dfsg-1)
sid: resolved (fixed in 1:1.19.10+dfsg-1)
trixie: resolved (fixed in 1:1.19.10+dfsg-1)
GHSA
GHSA-423m-g5gq-97wq: Cross-site scripting (XSS) vulnerability in MediaWiki 1
ghsa_unreviewed·2022-05-05
CVE-2013-6451 [MEDIUM] GHSA-423m-g5gq-97wq: Cross-site scripting (XSS) vulnerability in MediaWiki 1
Cross-site scripting (XSS) vulnerability in MediaWiki 1.19.9 before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to inject arbitrary web script or HTML via unspecified CSS values.
OSV
CVE-2013-6451: Cross-site scripting (XSS) vulnerability in MediaWiki 1
osv·2020-01-28·CVSS 6.1
CVE-2013-6451 [MEDIUM] CVE-2013-6451: Cross-site scripting (XSS) vulnerability in MediaWiki 1
Cross-site scripting (XSS) vulnerability in MediaWiki 1.19.9 before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to inject arbitrary web script or HTML via unspecified CSS values.
No detection rules found.
No public exploits indexed.
Bugzilla
New mediawiki security releases have been released
bugzilla·2014-01-14·CVSS 6.1
CVE-2013-6452 [MEDIUM] New mediawiki security releases have been released
New mediawiki security releases have been released
New versions:
1.19.10
1.21.4
1.22.1
Bugs fixed:
- (bug 57550) (CVE-2013-6452) SECURITY: Disallow stylesheets in SVG Uploads
- (bug 58088) (CVE-2013-6451) SECURITY: Don't normalize U+FF3C to \ in CSS Checks
- (bug 58472) (CVE-2013-6454) SECURITY: Disallow -o-link in styles
- (bug 58553) (CVE-2013-6453) SECURITY: Return error on invalid XML for SVG Uploads
- (bug 58699) (CVE-2013-6472) SECURITY: Fix RevDel log entry information leaks
Discussion:
mediawiki119-1.19.10-1.el6 has been submitted as an update for Fedora EPEL 6.
https://admin.fedoraproject.org/updates/mediawiki119-1.19.10-1.el6
---
mediawiki-1.19.10-1.fc18 has been submitted as an update for Fedora 18.
https://admin.fedoraproject.org/updates/mediawiki-1.19.10-1.fc18
---
me
Bugzilla
CVE-2013-6472 CVE-2013-6451 CVE-2013-6452 CVE-2013-6453 mediawiki119: mediawiki: security releases 1.22.1, 1.21.4 and 1.19.10 [epel-6]
bugzilla·2014-01-14·CVSS 6.1
CVE-2013-6472 [MEDIUM] CVE-2013-6472 CVE-2013-6451 CVE-2013-6452 CVE-2013-6453 mediawiki119: mediawiki: security releases 1.22.1, 1.21.4 and 1.19.10 [epel-6]
CVE-2013-6472 CVE-2013-6451 CVE-2013-6452 CVE-2013-6453 mediawiki119: mediawiki: security releases 1.22.1, 1.21.4 and 1.19.10 [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bugzilla
CVE-2013-6451 CVE-2013-6452 CVE-2013-6453 CVE-2013-6454 CVE-2013-6472 mediawiki: security releases 1.22.1, 1.21.4 and 1.19.10
bugzilla·2014-01-14·CVSS 4.3
CVE-2013-6451 [MEDIUM] CVE-2013-6451 CVE-2013-6452 CVE-2013-6453 CVE-2013-6454 CVE-2013-6472 mediawiki: security releases 1.22.1, 1.21.4 and 1.19.10
CVE-2013-6451 CVE-2013-6452 CVE-2013-6453 CVE-2013-6454 CVE-2013-6472 mediawiki: security releases 1.22.1, 1.21.4 and 1.19.10
These flaws were fixed in the recently-released MediaWiki 1.22.1, 1.21.4, and 1.19.10 releases:
* MediaWiki user Michael M reported that the fix for bug 55332 (CVE-2013-4568) allowed insertion of escaped CSS values which could pass the CSS validation checks, resulting in XSS. (CVE-2013-6451)
* Chris from RationalWiki reported that SVG files could be uploaded that include external stylesheets, which could lead to XSS when an XSL was used to include JavaScript. (CVE-2013-6452)
https://bugzilla.wikimedia.org/show_bug.cgi?id=57550
* During internal review, it was discovered that MediaWiki's SVG sanitization could be bypassed when the XML was considered invalid. (CV
2020-01-28
Published