2.6
CVSSv2

CVE-2014-3966

Published: 06/06/2014 Updated: 29/12/2017
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in Special:PasswordReset in MediaWiki prior to 1.19.16, 1.21.x prior to 1.21.10, and 1.22.x prior to 1.22.7, when wgRawHtml is enabled, allows remote malicious users to inject arbitrary web script or HTML via an invalid username.

Vulnerable Product Search on Vulmon Subscribe to Product

mediawiki mediawiki 1.19.11

mediawiki mediawiki 1.19.12

mediawiki mediawiki 1.19.6

mediawiki mediawiki 1.19.7

mediawiki mediawiki 1.19.1

mediawiki mediawiki 1.19.10

mediawiki mediawiki 1.19.4

mediawiki mediawiki 1.19.5

mediawiki mediawiki 1.19.13

mediawiki mediawiki 1.19.14

mediawiki mediawiki 1.19.8

mediawiki mediawiki 1.19.9

mediawiki mediawiki

mediawiki mediawiki 1.19.0

mediawiki mediawiki 1.19.2

mediawiki mediawiki 1.19.3

mediawiki mediawiki 1.22.1

mediawiki mediawiki 1.22.2

mediawiki mediawiki 1.22.5

mediawiki mediawiki 1.22.3

mediawiki mediawiki 1.22.4

mediawiki mediawiki 1.22.6

mediawiki mediawiki 1.22.0

mediawiki mediawiki 1.21.1

mediawiki mediawiki 1.21.2

mediawiki mediawiki 1.21.3

mediawiki mediawiki 1.21.6

mediawiki mediawiki 1.21.7

mediawiki mediawiki 1.21

mediawiki mediawiki 1.21.9

mediawiki mediawiki 1.21.8

mediawiki mediawiki 1.21.4

mediawiki mediawiki 1.21.5

Vendor Advisories

Debian Bug report logs - #750527 mediawiki: CVE-2014-3966: Javascript inject by anonymous users on private wikis with $wgRawHtml enabled Package: mediawiki; Maintainer for mediawiki is Kunal Mehta <legoktm@debianorg>; Source for mediawiki is src:mediawiki (PTS, buildd, popcon) Reported by: Henri Salo <henri@nervfi> ...