MEDIUM
GHSA-6h86-9r5g-f2h5
Cross-site scripting vulnerability in includes/actions/InfoAction.php
Quick fix
GHSA-6h86-9r5g-f2h5 — mediawiki/core: upgrade to the fixed version with the command below.
composer require mediawiki/core:^1.21.9Details
Cross-site scripting (XSS) vulnerability in includes/actions/InfoAction.php in MediaWiki before 1.21.9 and 1.22.x before 1.22.6 allows remote attackers to inject arbitrary web script or HTML via the sort key in an info action.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/mediawiki/core
Introduced in:
1.22.0Fixed in: 1.22.6Fix
composer require mediawiki/core:^1.22.6References
- https://nvd.nist.gov/vuln/detail/CVE-2014-2853[ADVISORY]
- https://github.com/wikimedia/mediawiki-core/commit/0b695ae09aada343ab59be4a3c9963995a1143b6[WEB]
- https://bugzilla.redhat.com/show_bug.cgi?id=1091967[WEB]
- https://bugzilla.wikimedia.org/show_bug.cgi?id=63251[WEB]
- https://github.com/wikimedia/mediawiki[PACKAGE]
- https://www.mediawiki.org/wiki/Release_notes/1.21#Changes_since_1.21.8[WEB]
- https://www.mediawiki.org/wiki/Release_notes/1.22#Changes_since_1.22.5[WEB]
- http://lists.wikimedia.org/pipermail/mediawiki-announce/2014-April/000149.html[WEB]
- http://secunia.com/advisories/58262[WEB]
- http://www.securityfocus.com/bid/67068[WEB]
- http://www.securitytracker.com/id/1030161[WEB]