vulnerability
MediaWiki: Unspecified Security Vulnerability (CVE-2017-0371)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 5 | (AV:N/AC:L/Au:N/C:P/I:N/A:N) | Feb 18, 2022 | Mar 2, 2022 | May 9, 2022 |
Severity
5
CVSS
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
Published
Feb 18, 2022
Added
Mar 2, 2022
Modified
May 9, 2022
Description
MediaWiki before 1.23.16, 1.24.x through 1.27.x before 1.27.2, and 1.28.x before 1.28.1 allows remote attackers to discover the IP addresses of Wiki visitors via a style="background-image: attr(title url);" attack within a DIV element that has an attacker-controlled URL in the title attribute.
Solutions
mediawiki-upgrade-1_23_16mediawiki-upgrade-1_27_2mediawiki-upgrade-1_28_1
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.