MediaWiki is prone to the following security vulnerabilities:
1. Multiple cross-site scripting vulnerabilities
2. Multiple information-disclosure vulnerabilities
3. Multiple security-bypass vulnerabilities
4. An HTML-injection vulnerability
5. A denial-of-service vulnerability
6. A buffer-overflow vulnerability
7. A cross-site request forgery vulnerability
An attacker can exploit these issues to perform unauthorized actions, bypass security restrictions, cause denial-of-service conditions, execute attacker-supplied HTML or JavaScript code in the context of the affected site, to steal cookie-based authentication credentials, execute arbitrary code, or gain access to sensitive information.
Versions prior to MediaWiki 1.19.20, 1.21.4 and 1.22.1 are vulnerable.
Attackers can exploit this issue using a browser or readily available tools.
Solution: updates are available. Please see the references or vendor advisory for more information.
Full Article
Login to the community
No account yet? Create an account
Enter your username or e-mail address. We'll send you an e-mail with instructions to reset your password.