Debian Mediawiki vulnerabilities

304 known vulnerabilities affecting debian/mediawiki.

Total CVEs
304
CISA KEV
0
Public exploits
6
Exploited in wild
1
Severity breakdown
CRITICAL4HIGH47MEDIUM133LOW94UNKNOWN6

Vulnerabilities

Page 11 of 16
CVE-2014-2243MEDIUMCVSS 5.8fixed in mediawiki 1:1.19.12+dfsg-1 (bookworm)2014
CVE-2014-2243 [MEDIUM] CVE-2014-2243: mediawiki - includes/User.php in MediaWiki before 1.19.12, 1.20.x and 1.21.x before 1.21.6, ... includes/User.php in MediaWiki before 1.19.12, 1.20.x and 1.21.x before 1.21.6, and 1.22.x before 1.22.3 terminates validation of a user token upon encountering the first incorrect character, which makes it easier for remote attackers to obtain access via a brute-force attack that relies on timing differences in responses to incorrect token guesses. Scope: local b
debian
CVE-2014-2665MEDIUMCVSS 4.0fixed in mediawiki 1:1.19.14+dfsg-1 (bookworm)2014
CVE-2014-2665 [MEDIUM] CVE-2014-2665: mediawiki - includes/specials/SpecialChangePassword.php in MediaWiki before 1.19.14, 1.20.x ... includes/specials/SpecialChangePassword.php in MediaWiki before 1.19.14, 1.20.x and 1.21.x before 1.21.8, and 1.22.x before 1.22.5 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensitive information by arranging for a victim to login to the attacker's account, as demo
debian
CVE-2014-5243MEDIUMCVSS 4.3fixed in mediawiki 1:1.19.18+dfsg-0.1 (bookworm)2014
CVE-2014-5243 [MEDIUM] CVE-2014-5243: mediawiki - MediaWiki before 1.19.18, 1.20.x through 1.22.x before 1.22.9, and 1.23.x before... MediaWiki before 1.19.18, 1.20.x through 1.22.x before 1.22.9, and 1.23.x before 1.23.2 does not enforce an IFRAME protection mechanism for transcluded pages, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site. Scope: local bookworm: resolved (fixed in 1:1.19.18+dfsg-0.1) bullseye: resolved (fixed in 1:1.19.18+dfsg-0.
debian
CVE-2014-7199MEDIUMCVSS 4.3fixed in mediawiki 1:1.19.19+dfsg-1 (bookworm)2014
CVE-2014-7199 [MEDIUM] CVE-2014-7199: mediawiki - Cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.19, 1.22.x bef... Cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.19, 1.22.x before 1.22.11, and 1.23.x before 1.23.4 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG file. Scope: local bookworm: resolved (fixed in 1:1.19.19+dfsg-1) bullseye: resolved (fixed in 1:1.19.19+dfsg-1) forky: resolved (fixed in 1:1.19.19+dfsg-1) sid: resol
debian
CVE-2014-2242MEDIUMCVSS 4.3fixed in mediawiki 1:1.19.12+dfsg-1 (bookworm)2014
CVE-2014-2242 [MEDIUM] CVE-2014-2242: mediawiki - includes/upload/UploadBase.php in MediaWiki before 1.19.12, 1.20.x and 1.21.x be... includes/upload/UploadBase.php in MediaWiki before 1.19.12, 1.20.x and 1.21.x before 1.21.6, and 1.22.x before 1.22.3 does not prevent use of invalid namespaces in SVG files, which allows remote attackers to conduct cross-site scripting (XSS) attacks via an SVG upload, as demonstrated by use of a W3C XHTML namespace in conjunction with an IFRAME element. Scope: lo
debian
CVE-2014-1610MEDIUMCVSS 6.0PoCfixed in mediawiki 1:1.19.11+dfsg-1 (bookworm)2014
CVE-2014-1610 [MEDIUM] CVE-2014-1610: mediawiki - MediaWiki 1.22.x before 1.22.2, 1.21.x before 1.21.5, and 1.19.x before 1.19.11,... MediaWiki 1.22.x before 1.22.2, 1.21.x before 1.21.5, and 1.19.x before 1.19.11, when DjVu or PDF file upload support is enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the page parameter to includes/media/DjVu.php; (2) the w parameter (aka width field) to thumb.php, which is not properly handled by includes/media/Pdf
debian
CVE-2014-9507LOWCVSS 2.62014
CVE-2014-9507 [LOW] CVE-2014-9507: mediawiki - MediaWiki 1.21.x, 1.22.x before 1.22.14, and 1.23.x before 1.23.7, when $wgConte... MediaWiki 1.21.x, 1.22.x before 1.22.14, and 1.23.x before 1.23.7, when $wgContentHandlerUseDB is enabled, allows remote attackers to conduct cross-site scripting (XSS) attacks by setting the content model for a revision to JS. Scope: local bookworm: resolved bullseye: resolved forky: resolved sid: resolved trixie: resolved
debian
CVE-2014-2853LOWCVSS 4.32014
CVE-2014-2853 [MEDIUM] CVE-2014-2853: mediawiki - Cross-site scripting (XSS) vulnerability in includes/actions/InfoAction.php in M... Cross-site scripting (XSS) vulnerability in includes/actions/InfoAction.php in MediaWiki before 1.21.9 and 1.22.x before 1.22.6 allows remote attackers to inject arbitrary web script or HTML via the sort key in an info action. Scope: local bookworm: resolved bullseye: resolved forky: resolved sid: resolved trixie: resolved
debian
CVE-2014-3966LOWCVSS 2.6fixed in mediawiki 1:1.19.16+dfsg-1 (bookworm)2014
CVE-2014-3966 [LOW] CVE-2014-3966: mediawiki - Cross-site scripting (XSS) vulnerability in Special:PasswordReset in MediaWiki b... Cross-site scripting (XSS) vulnerability in Special:PasswordReset in MediaWiki before 1.19.16, 1.21.x before 1.21.10, and 1.22.x before 1.22.7, when wgRawHtml is enabled, allows remote attackers to inject arbitrary web script or HTML via an invalid username. Scope: local bookworm: resolved (fixed in 1:1.19.16+dfsg-1) bullseye: resolved (fixed in 1:1.19.16+dfsg-1) for
debian
CVE-2014-7295LOWCVSS 3.5fixed in mediawiki 1:1.19.20+dfsg-1 (bookworm)2014
CVE-2014-7295 [LOW] CVE-2014-7295: mediawiki - The (1) Special:Preferences and (2) Special:UserLogin pages in MediaWiki before ... The (1) Special:Preferences and (2) Special:UserLogin pages in MediaWiki before 1.19.20, 1.22.x before 1.22.12 and 1.23.x before 1.23.5 allows remote authenticated users to conduct cross-site scripting (XSS) attacks or have unspecified other impact via crafted CSS, as demonstrated by modifying MediaWiki:Common.css. Scope: local bookworm: resolved (fixed in 1:1.19.20+
debian
CVE-2014-9476LOWCVSS 5.02014
CVE-2014-9476 [MEDIUM] CVE-2014-9476: mediawiki - MediaWiki 1.2x before 1.22.15, 1.23.x before 1.23.8, and 1.24.x before 1.24.1 al... MediaWiki 1.2x before 1.22.15, 1.23.x before 1.23.8, and 1.24.x before 1.24.1 allows remote attackers to bypass CORS restrictions in $wgCrossSiteAJAXdomains via a domain that has a partial match to an allowed origin, as demonstrated by "http://en.wikipedia.org.evilsite.example/." Scope: local bookworm: resolved bullseye: resolved forky: resolved sid: resolved trix
debian
CVE-2014-9475LOWCVSS 3.5fixed in mediawiki 1:1.19.20+dfsg-2.2 (bookworm)2014
CVE-2014-9475 [LOW] CVE-2014-9475: mediawiki - Cross-site scripting (XSS) vulnerability in thumb.php in MediaWiki before 1.19.2... Cross-site scripting (XSS) vulnerability in thumb.php in MediaWiki before 1.19.23, 1.2x before 1.22.15, 1.23.x before 1.23.8, and 1.24.x before 1.24.1 allows remote authenticated users to inject arbitrary web script or HTML via a wikitext message. Scope: local bookworm: resolved (fixed in 1:1.19.20+dfsg-2.2) bullseye: resolved (fixed in 1:1.19.20+dfsg-2.2) forky: res
debian
CVE-2014-9276LOWCVSS 5.12014
CVE-2014-9276 [MEDIUM] CVE-2014-9276: mediawiki - Cross-site request forgery (CSRF) vulnerability in the Special:ExpandedTemplates... Cross-site request forgery (CSRF) vulnerability in the Special:ExpandedTemplates page in MediaWiki before 1.19.22, 1.20.x through 1.22.x before 1.22.14, and 1.23.x before 1.23.7, when $wgRawHTML is set to true, allows remote attackers to hijack the authentication of users with edit permissions for requests that cross-site scripting (XSS) attacks via the wpInput pa
debian
CVE-2014-5242LOWCVSS 4.32014
CVE-2014-5242 [MEDIUM] CVE-2014-5242: mediawiki - Cross-site scripting (XSS) vulnerability in mediawiki.page.image.pagination.js i... Cross-site scripting (XSS) vulnerability in mediawiki.page.image.pagination.js in MediaWiki 1.22.x before 1.22.9 and 1.23.x before 1.23.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving the multipageimagenavbox class in conjunction with an action=raw value. Scope: local bookworm: resolved bullseye: resolved forky: resolved sid:
debian
CVE-2014-2244LOWCVSS 4.32014
CVE-2014-2244 [MEDIUM] CVE-2014-2244: mediawiki - Cross-site scripting (XSS) vulnerability in the formatHTML function in includes/... Cross-site scripting (XSS) vulnerability in the formatHTML function in includes/api/ApiFormatBase.php in MediaWiki before 1.19.12, 1.20.x and 1.21.x before 1.21.6, and 1.22.x before 1.22.3 allows remote attackers to inject arbitrary web script or HTML via a crafted string located after http:// in the text parameter to api.php. Scope: local bookworm: resolved bulls
debian
CVE-2013-6453HIGHCVSS 7.5fixed in mediawiki 1:1.19.10+dfsg-1 (bookworm)2013
CVE-2013-6453 [HIGH] CVE-2013-6453: mediawiki - MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 does not ... MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 does not properly sanitize SVG files, which allows remote attackers to have unspecified impact via invalid XML. Scope: local bookworm: resolved (fixed in 1:1.19.10+dfsg-1) bullseye: resolved (fixed in 1:1.19.10+dfsg-1) forky: resolved (fixed in 1:1.19.10+dfsg-1) sid: resolved (fixed in 1:1.19.10+
debian
CVE-2013-4572HIGHCVSS 7.5fixed in mediawiki 1:1.19.8+dfsg-2.2 (bookworm)2013
CVE-2013-4572 [HIGH] CVE-2013-4572: mediawiki - The CentralNotice extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, a... The CentralNotice extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 sets the Cache-Control header to cache session cookies when a user is autocreated, which allows remote attackers to authenticate as the created user. Scope: local bookworm: resolved (fixed in 1:1.19.8+dfsg-2.2) bullseye: resolved (fixed in 1:1.19.8+dfsg-2.2) forky
debian
CVE-2013-1816HIGHCVSS 7.5fixed in mediawiki 1:1.19.4-1 (bookworm)2013
CVE-2013-1816 [HIGH] CVE-2013-1816: mediawiki - MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remote attackers to caus... MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remote attackers to cause a denial of service (application crash) by sending a specially crafted request. Scope: local bookworm: resolved (fixed in 1:1.19.4-1) bullseye: resolved (fixed in 1:1.19.4-1) forky: resolved (fixed in 1:1.19.4-1) sid: resolved (fixed in 1:1.19.4-1) trixie: resolved (fixed in 1:1.19.4-1
debian
CVE-2013-1817HIGHCVSS 7.5fixed in mediawiki 1:1.19.4-1 (bookworm)2013
CVE-2013-1817 [HIGH] CVE-2013-1817: mediawiki - MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.ph... MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.php script which allows remote attackers to obtain sensitive information. Scope: local bookworm: resolved (fixed in 1:1.19.4-1) bullseye: resolved (fixed in 1:1.19.4-1) forky: resolved (fixed in 1:1.19.4-1) sid: resolved (fixed in 1:1.19.4-1) trixie: resolved (fixed in 1:1.19.4-1)
debian
CVE-2013-4302MEDIUMCVSS 5.0fixed in mediawiki 1:1.19.8+dfsg-1 (bookworm)2013
CVE-2013-4302 [MEDIUM] CVE-2013-4302: mediawiki - (1) ApiBlock.php, (2) ApiCreateAccount.php, (3) ApiLogin.php, (4) ApiMain.php, (... (1) ApiBlock.php, (2) ApiCreateAccount.php, (3) ApiLogin.php, (4) ApiMain.php, (5) ApiQueryDeletedrevs.php, (6) ApiTokens.php, and (7) ApiUnblock.php in includes/api/ in MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 allow remote attackers to obtain CSRF tokens and bypass the cross-site request forgery (CSRF) protection mechanism vi
debian