Input validation error in MediaWiki - CVE-2014-5243
Published: August 22, 2014 / Updated: August 10, 2020
MediaWiki
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to manipulate data.
MediaWiki before 1.19.18, 1.20.x through 1.22.x before 1.22.9, and 1.23.x before 1.23.2 does not enforce an IFRAME protection mechanism for transcluded pages, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site.
How to mitigate CVE-2014-5243
Sources
- http://advisories.mageia.org/MGASA-2014-0309.html
- http://openwall.com/lists/oss-security/2014/08/14/5
- http://secunia.com/advisories/59738
- http://www.debian.org/security/2014/dsa-3011
- http://www.mandriva.com/security/advisories?name=MDVSA-2014:153
- https://bugzilla.wikimedia.org/show_bug.cgi?id=65778
- https://lists.wikimedia.org/pipermail/mediawiki-announce/2014-July/000157.html