Text Manipulation Vulnerability in MediaWiki by Wikimedia Foundation
CVE-2017-8814

7.5HIGH

What is CVE-2017-8814?

The language converter in MediaWiki, specifically versions below 1.27.4, 1.28.x below 1.28.3, and 1.29.x below 1.29.2, contains a vulnerability that permits attackers to manipulate text within HTML tags. By leveraging a crafted rule definition, an attacker can insert harmful content, potentially compromising the integrity of the text displayed. This vulnerability poses significant risks for websites and applications relying on MediaWiki for content management.

Affected Version(s)

MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.