CVE-2015-2935Sensitive Information Exposure in Mediawiki

Severity
5.0MEDIUMNVD
EPSS
0.3%
top 46.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 13
Latest updateMay 17

Description

MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to bypass the SVG filtering and obtain sensitive user information via a mixed case @import in a style element in an SVG file, as demonstrated by "@imporT."

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

debiandebian/mediawiki< mediawiki 1:1.19.20+dfsg-2.3 (bookworm)
Debianmediawiki/mediawiki< 1:1.19.20+dfsg-2.3+3
NVDmediawiki/mediawiki1.19.23+48

Patches

🔴Vulnerability Details

2
GHSA
GHSA-7955-v6mw-3hh5: MediaWiki before 12022-05-17
OSV
CVE-2015-2935: MediaWiki before 12015-04-13

📋Vendor Advisories

1
Debian
CVE-2015-2935: mediawiki - MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows re...2015
CVE-2015-2935 — Sensitive Information Exposure | cvebase