Cross-site scripting (XSS) vulnerability in MediaWiki before 1.6.11, 1.12.x before 1.12.2, and 1.13.x before 1.13.3, when Internet Explorer is used and uploads are enabled, or an SVG scripting browser is used and SVG uploads are enabled, allows remote authenticated users to inject arbitrary web script or HTML by editing a wiki page.
CVSS Details
- CVSS 3.1 Base Score: 5.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade mediawiki | Jul 30, 2024 | Dec 19, 2008 |
| Freebsd | — | Upgrade mediawiki | Dec 10, 2025 | Dec 19, 2008 |
| Mediawiki | — | Upgrade MediaWiki to the latest version | Aug 24, 2017 | Dec 19, 2008 |
| Suse | — | Upgrade mediawiki | Feb 17, 2015 | Dec 19, 2008 |
| Ubuntu | — | Upgrade mediawiki | Nov 19, 2024 | Dec 19, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub