4.3
CVSSv2

CVE-2012-1582

Published: 09/09/2012 Updated: 29/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the wikitext parser in MediaWiki 1.17.x prior to 1.17.3 and 1.18.x prior to 1.18.2 allows remote malicious users to inject arbitrary web script or HTML via a crafted page with "forged strip item markers," as demonstrated using the CharInsert extension.

Vulnerable Product Search on Vulmon Subscribe to Product

mediawiki mediawiki 1.17

mediawiki mediawiki 1.17.1

mediawiki mediawiki 1.17.2

mediawiki mediawiki 1.17.0

mediawiki mediawiki 1.18

mediawiki mediawiki 1.18.0

mediawiki mediawiki 1.18.1

Vendor Advisories

Debian Bug report logs - #666269 mediawiki: security release CVE-2012-1578/CVE-2012-1579/CVE-2012-1580/CVE-2012-1581/CVE-2012-1582 Package: mediawiki; Maintainer for mediawiki is Kunal Mehta <legoktm@debianorg>; Source for mediawiki is src:mediawiki (PTS, buildd, popcon) Reported by: Henri Salo <henri@nervfi> Date: ...