MediaWiki 'InfoAction.php' HTML Injection Vulnerability
BID:67068
Info
MediaWiki 'InfoAction.php' HTML Injection Vulnerability
| Bugtraq ID: | 67068 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-2853 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 24 2014 12:00AM |
| Updated: | Apr 13 2015 09:56PM |
| Credit: | Dr. Cindy Cicalese of MITRE Corporation |
| Vulnerable: |
MediaWiki Mediawiki 1.21.4 MediaWiki Mediawiki 1.21.3 MediaWiki Mediawiki 1.21.2 MediaWiki Mediawiki 1.21.1 MediaWiki Mediawiki 1.22.5 MediaWiki Mediawiki 1.22.4 MediaWiki Mediawiki 1.22.3 MediaWiki Mediawiki 1.22.2 MediaWiki Mediawiki 1.22.1 MediaWiki Mediawiki 1.22.0 MediaWiki Mediawiki 1.21.8 MediaWiki Mediawiki 1.21.7 MediaWiki Mediawiki 1.21.6 MediaWiki Mediawiki 1.21.5 MediaWiki Mediawiki 1.21 |
| Not Vulnerable: |
MediaWiki Mediawiki 1.22.6 MediaWiki Mediawiki 1.21.9 |
Discussion
MediaWiki 'InfoAction.php' HTML Injection Vulnerability
MediaWiki is prone to a HTML-injection vulnerability because it fails to properly sanitize user-supplied input.
Attacker supplied HTML and script code would run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or control how the site is rendered to the user. Other attacks are also possible.
MediaWiki prior 1.21.9 and 1.22.6 are vulnerable.
MediaWiki is prone to a HTML-injection vulnerability because it fails to properly sanitize user-supplied input.
Attacker supplied HTML and script code would run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or control how the site is rendered to the user. Other attacks are also possible.
MediaWiki prior 1.21.9 and 1.22.6 are vulnerable.
Exploit / POC
MediaWiki 'InfoAction.php' HTML Injection Vulnerability
Attackers can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
Attackers can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.