CVE-2015-2932Cross-site Scripting in Mediawiki

Severity
4.3MEDIUMNVD
EPSS
0.3%
top 48.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 13
Latest updateMay 17

Description

Incomplete blacklist vulnerability in MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to inject arbitrary web script or HTML via an animated href XLink element.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

debiandebian/mediawiki< mediawiki 1:1.19.20+dfsg-2.3 (bookworm)
Debianmediawiki/mediawiki< 1:1.19.20+dfsg-2.3+3
NVDmediawiki/mediawiki1.19.23+48

Patches

🔴Vulnerability Details

2
GHSA
GHSA-p23q-m853-q3rp: Incomplete blacklist vulnerability in MediaWiki before 12022-05-17
OSV
CVE-2015-2932: Incomplete blacklist vulnerability in MediaWiki before 12015-04-13

📋Vendor Advisories

1
Debian
CVE-2015-2932: mediawiki - Incomplete blacklist vulnerability in MediaWiki before 1.19.24, 1.2x before 1.23...2015
CVE-2015-2932 — Cross-site Scripting in Mediawiki | cvebase