XSS Vulnerability in MediaWiki Affects Multiple Versions
CVE-2017-8808
6.1MEDIUM
Key Information:
- Vendor
Mediawiki
- Vendor
- CVE Published:
- 15 November 2017
What is CVE-2017-8808?
An XSS vulnerability exists in MediaWiki versions prior to 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2. This issue arises when the $wgShowExceptionDetails setting is set to false, allowing attackers to exploit non-standard URL escaping in browsers. This could lead to the execution of arbitrary scripts in the context of the user’s session.
Affected Version(s)
MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2
