Cross-site scripting in MediaWiki - CVE-2015-2932

 

Cross-site scripting in MediaWiki - CVE-2015-2932

Published: April 13, 2015 / Updated: August 9, 2020


Vulnerability identifier: #VU40836
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2015-2932
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: MediaWiki.org
Affected software:
MediaWiki

Detailed vulnerability description

The vulnerability allows a remote non-authenticated attacker to manipulate data.

Incomplete blacklist vulnerability in MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to inject arbitrary web script or HTML via an animated href XLink element.


How to mitigate CVE-2015-2932

Install update from vendor's website.

Sources