CVE-2014-2242
published 2014-03-02CVE-2014-2242: includes/upload/UploadBase.php in MediaWiki before 1.19.12, 1.20.x and 1.21.x before 1.21.6, and 1.22.x before 1.22.3 does not prevent use of invalid…
PriorityP421medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.45%
82.7th percentile
includes/upload/UploadBase.php in MediaWiki before 1.19.12, 1.20.x and 1.21.x before 1.21.6, and 1.22.x before 1.22.3 does not prevent use of invalid namespaces in SVG files, which allows remote attackers to conduct cross-site scripting (XSS) attacks via an SVG upload, as demonstrated by use of a W3C XHTML namespace in conjunction with an IFRAME element.
Affected
78 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mediawiki | < mediawiki 1:1.19.12+dfsg-1 (bookworm) | mediawiki 1:1.19.12+dfsg-1 (bookworm) |
| mediawiki | mediawiki | <= 1.19.11 | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xvhv-fm6p-g8q4: includes/upload/UploadBase
ghsa_unreviewed·2022-05-17
CVE-2014-2242 [MEDIUM] CWE-79 GHSA-xvhv-fm6p-g8q4: includes/upload/UploadBase
includes/upload/UploadBase.php in MediaWiki before 1.19.12, 1.20.x and 1.21.x before 1.21.6, and 1.22.x before 1.22.3 does not prevent use of invalid namespaces in SVG files, which allows remote attackers to conduct cross-site scripting (XSS) attacks via an SVG upload, as demonstrated by use of a W3C XHTML namespace in conjunction with an IFRAME element.
OSV
CVE-2014-2242: includes/upload/UploadBase
osv·2014-03-02·CVSS 4.3
CVE-2014-2242 [MEDIUM] CVE-2014-2242: includes/upload/UploadBase
includes/upload/UploadBase.php in MediaWiki before 1.19.12, 1.20.x and 1.21.x before 1.21.6, and 1.22.x before 1.22.3 does not prevent use of invalid namespaces in SVG files, which allows remote attackers to conduct cross-site scripting (XSS) attacks via an SVG upload, as demonstrated by use of a W3C XHTML namespace in conjunction with an IFRAME element.
Debian
CVE-2014-2242: mediawiki - includes/upload/UploadBase.php in MediaWiki before 1.19.12, 1.20.x and 1.21.x be...
vendor_debian·2014·CVSS 4.3
CVE-2014-2242 [MEDIUM] CVE-2014-2242: mediawiki - includes/upload/UploadBase.php in MediaWiki before 1.19.12, 1.20.x and 1.21.x be...
includes/upload/UploadBase.php in MediaWiki before 1.19.12, 1.20.x and 1.21.x before 1.21.6, and 1.22.x before 1.22.3 does not prevent use of invalid namespaces in SVG files, which allows remote attackers to conduct cross-site scripting (XSS) attacks via an SVG upload, as demonstrated by use of a W3C XHTML namespace in conjunction with an IFRAME element.
Scope: local
bookworm: resolved (fixed in 1:1.19.12+dfsg-1)
bullseye: resolved (fixed in 1:1.19.12+dfsg-1)
forky: resolved (fixed in 1:1.19.12+dfsg-1)
sid: resolved (fixed in 1:1.19.12+dfsg-1)
trixie: resolved (fixed in 1:1.19.12+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-2242 mediawiki119: mediawiki: cross-site scripting flaw when handling SVG images [epel-5]
bugzilla·2014-04-28·CVSS 4.3
CVE-2014-2242 [MEDIUM] CVE-2014-2242 mediawiki119: mediawiki: cross-site scripting flaw when handling SVG images [epel-5]
CVE-2014-2242 mediawiki119: mediawiki: cross-site scripting flaw when handling SVG images [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-5 t
Bugzilla
CVE-2014-2242 mediawiki: cross-site scripting flaw when handling SVG images
bugzilla·2014-02-28·CVSS 4.3
CVE-2014-2242 [MEDIUM] CVE-2014-2242 mediawiki: cross-site scripting flaw when handling SVG images
CVE-2014-2242 mediawiki: cross-site scripting flaw when handling SVG images
The MediaWiki 1.22.3, 1.21.6 and 1.19.12 release announcement notes:
* (bug 60771) SECURITY: Disallow uploading SVG files using non-whitelisted
namespaces. Also disallow iframe elements. User will get an error
including the namespace name if they use a non- whitelisted namespace.
An attacker could perform cross-site scripting attacks by uploading crafted SVG images.
The versions of MediaWiki in Fedora and EPEL 6 are affected. I have not tested EPEL 5.
References:
http://lists.wikimedia.org/pipermail/mediawiki-announce/2014-February/000141.html
https://bugzilla.wikimedia.org/show_bug.cgi?id=60771
https://gerrit.wikimedia.org/r/#/q/7d923a6b53f7fbcb0cbc3a19797d741bf6f440eb,n,z
Discussion:
Created mediawiki trac
http://lists.wikimedia.org/pipermail/mediawiki-announce/2014-February/000141.htmlhttp://openwall.com/lists/oss-security/2014/02/28/1http://openwall.com/lists/oss-security/2014/03/01/2http://www.securityfocus.com/bid/65910https://bugzilla.redhat.com/show_bug.cgi?id=1071135https://bugzilla.wikimedia.org/show_bug.cgi?id=60771https://gerrit.wikimedia.org/r/#/q/7d923a6b53f7fbcb0cbc3a19797d741bf6f440eb%2Cn%2Czhttp://lists.wikimedia.org/pipermail/mediawiki-announce/2014-February/000141.htmlhttp://openwall.com/lists/oss-security/2014/02/28/1http://openwall.com/lists/oss-security/2014/03/01/2http://www.securityfocus.com/bid/65910https://bugzilla.redhat.com/show_bug.cgi?id=1071135https://bugzilla.wikimedia.org/show_bug.cgi?id=60771https://gerrit.wikimedia.org/r/#/q/7d923a6b53f7fbcb0cbc3a19797d741bf6f440eb%2Cn%2Cz
2014-03-02
Published