XSS Vulnerability in MobileFrontend Extension for MediaWiki
CVE-2019-14807

6.1MEDIUM

Key Information:

Vendor

Mediawiki

Vendor
CVE Published:
9 August 2019

What is CVE-2019-14807?

A Cross-Site Scripting (XSS) vulnerability exists in the MobileFrontend extension for MediaWiki, specifically affecting versions 1.31 through 1.33. This flaw allows attackers to inject malicious scripts via the edit summary field in MobileSpecialPageFeed.php, potentially compromising the security of users interacting with the application. It highlights the importance of sanitizing user inputs to prevent XSS attacks and ensures robust security measures are implemented.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.