Cross-site scripting in MediaWiki - CVE-2011-0047
Published: February 4, 2011 / Updated: December 22, 2020
MediaWiki
Detailed vulnerability description
Vulnerability allows a remote attacker to perform Cross-site scripting attacks.
An input validation error exists in MediaWiki before 1.16.2. A remote authenticated attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in victim's browser in security context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
How to mitigate CVE-2011-0047
Sources
- http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058910.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-April/059232.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-April/059235.html
- http://lists.wikimedia.org/pipermail/mediawiki-announce/2011-February/000095.html
- http://osvdb.org/70770
- http://secunia.com/advisories/43142
- http://www.securityfocus.com/bid/46108
- http://www.vupen.com/english/advisories/2011/0273
- https://bugzilla.wikimedia.org/show_bug.cgi?id=27093
- https://exchange.xforce.ibmcloud.com/vulnerabilities/65126