CVE-2017-8812Mediawiki vulnerability

4 documents4 sources
Severity
5.3MEDIUMNVD
EPSS
0.8%
top 25.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 15
Latest updateMay 13

Description

MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows remote attackers to inject > (greater than) characters via the id attribute of a headline.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages3 packages

debiandebian/mediawiki< mediawiki 1:1.27.4-1 (bookworm)
Debianmediawiki/mediawiki< 1:1.27.4-1+3
NVDmediawiki/mediawiki1.27.3+5

Also affects: Debian Linux 9.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-7c6g-3j56-238r: MediaWiki before 12022-05-13
OSV
CVE-2017-8812: MediaWiki before 12017-11-15

📋Vendor Advisories

1
Debian
CVE-2017-8812: mediawiki - MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows r...2017
CVE-2017-8812 — Debian Mediawiki vulnerability | cvebase