CVE-2013-6453 — Improper Input Validation in Mediawiki
Severity
7.5HIGHNVD
EPSS
0.6%
top 29.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 12
Latest updateMay 17
Description
MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 does not properly sanitize SVG files, which allows remote attackers to have unspecified impact via invalid XML.
CVSS vector
AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4
Affected Packages3 packages
Patches
🔴Vulnerability Details
2📋Vendor Advisories
1Debian▶
CVE-2013-6453: mediawiki - MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 does not ...↗2013