XSS Vulnerability in MediaWiki Affects Multiple Versions
CVE-2017-8808

6.1MEDIUM

What is CVE-2017-8808?

An XSS vulnerability exists in MediaWiki versions prior to 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2. This issue arises when the $wgShowExceptionDetails setting is set to false, allowing attackers to exploit non-standard URL escaping in browsers. This could lead to the execution of arbitrary scripts in the context of the user’s session.

Affected Version(s)

MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.