CVE-2013-4303
Summary
| CVE | CVE-2013-4303 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-12-11 19:15:00 UTC |
| Updated | 2019-12-19 17:37:00 UTC |
| Description | includes/libs/IEUrlExtension.php in the MediaWiki API in MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 does not properly detect extensions when there are an even number of "." (period) characters in a string, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the siprop parameter in a query action to wiki/api.php. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [MediaWiki-announce] MediaWiki Security Release: 1.21.2, 1.20.7 and 1.19.8 | MISC | lists.wikimedia.org | Mailing List, Patch, Vendor Advisory |
| IBM X-Force Exchange | MISC | exchange.xforce.ibmcloud.com | Third Party Advisory, VDB Entry |
| oss-sec: Re: CVE request: MediaWiki Security Release: 1.21.2, 1.20.7 and 1.19.8 | MISC | seclists.org | Mailing List, Third Party Advisory |
| Mediawiki CVE-2013-4303 Cross Site Scripting Vulnerability | MISC | www.securityfocus.com | Third Party Advisory, VDB Entry |
| ⚓ T54746 XSS in MediaWiki API (through invalid property name) reintroduced in 1.21.1 | MISC | bugzilla.wikimedia.org | Exploit, Issue Tracking, Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.