CVE-2014-3966Cross-site Scripting in Mediawiki

Severity
2.6LOWNVD
EPSS
0.3%
top 44.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 6
Latest updateMay 14

Description

Cross-site scripting (XSS) vulnerability in Special:PasswordReset in MediaWiki before 1.19.16, 1.21.x before 1.21.10, and 1.22.x before 1.22.7, when wgRawHtml is enabled, allows remote attackers to inject arbitrary web script or HTML via an invalid username.

CVSS vector

AV:N/AC:H/C:N/I:P/A:NExploitability: 4.9 | Impact: 2.9

Affected Packages3 packages

debiandebian/mediawiki< mediawiki 1:1.19.16+dfsg-1 (bookworm)
Debianmediawiki/mediawiki< 1:1.19.16+dfsg-1+3
NVDmediawiki/mediawiki1.19.15+32

Patches

🔴Vulnerability Details

2
GHSA
GHSA-6789-p69v-h59w: Cross-site scripting (XSS) vulnerability in Special:PasswordReset in MediaWiki before 12022-05-14
OSV
CVE-2014-3966: Cross-site scripting (XSS) vulnerability in Special:PasswordReset in MediaWiki before 12014-06-06

📋Vendor Advisories

1
Debian
CVE-2014-3966: mediawiki - Cross-site scripting (XSS) vulnerability in Special:PasswordReset in MediaWiki b...2014

💬Community

1
Bugzilla
CVE-2014-3966 mediawiki: XSS flaw due to improper parsing of Special:PasswordReset2014-06-03
CVE-2014-3966 — Cross-site Scripting in Mediawiki | cvebase