CVE-2017-8808Cross-site Scripting in Mediawiki

Severity
6.1MEDIUMNVD
EPSS
0.4%
top 39.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 15
Latest updateMay 17

Description

MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 has XSS when the $wgShowExceptionDetails setting is false and the browser sends non-standard URL escaping.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages3 packages

debiandebian/mediawiki< mediawiki 1:1.27.4-1 (bookworm)
Debianmediawiki/mediawiki< 1:1.27.4-1+3
NVDmediawiki/mediawiki1.27.3+5

Also affects: Debian Linux 9.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-82j7-474r-g29g: MediaWiki before 12022-05-17
OSV
CVE-2017-8808: MediaWiki before 12017-11-15

📋Vendor Advisories

1
Debian
CVE-2017-8808: mediawiki - MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 has XSS ...2017
CVE-2017-8808 — Cross-site Scripting in Mediawiki | cvebase