6.8
CVSSv2

CVE-2014-5241

Published: 22/08/2014 Updated: 07/01/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The JSONP endpoint in includes/api/ApiFormatJson.php in MediaWiki prior to 1.19.18, 1.20.x up to and including 1.22.x prior to 1.22.9, and 1.23.x prior to 1.23.2 accepts certain long callback values and does not restrict the initial bytes of a JSONP response, which allows remote malicious users to conduct cross-site request forgery (CSRF) attacks, and obtain sensitive information, via a crafted OBJECT element with SWF content consistent with a restricted character set.

Vulnerable Product Search on Vulmon Subscribe to Product

mediawiki mediawiki 1.19.10

mediawiki mediawiki 1.21.1

mediawiki mediawiki 1.21.7

mediawiki mediawiki 1.21.8

mediawiki mediawiki 1.20.4

mediawiki mediawiki 1.20.5

mediawiki mediawiki

mediawiki mediawiki 1.19.2

mediawiki mediawiki 1.19.9

mediawiki mediawiki 1.22.7

mediawiki mediawiki 1.22.0

mediawiki mediawiki 1.22.8

mediawiki mediawiki 1.19

mediawiki mediawiki 1.19.0

mediawiki mediawiki 1.19.1

mediawiki mediawiki 1.21.5

mediawiki mediawiki 1.21.6

mediawiki mediawiki 1.20.2

mediawiki mediawiki 1.20.3

mediawiki mediawiki 1.19.15

mediawiki mediawiki 1.19.16

mediawiki mediawiki 1.19.7

mediawiki mediawiki 1.19.8

mediawiki mediawiki 1.22.2

mediawiki mediawiki 1.22.1

mediawiki mediawiki 1.21.3

mediawiki mediawiki 1.21.4

mediawiki mediawiki 1.19.12

mediawiki mediawiki 1.20.1

mediawiki mediawiki 1.20.8

mediawiki mediawiki 1.19.13

mediawiki mediawiki 1.19.14

mediawiki mediawiki 1.19.5

mediawiki mediawiki 1.19.6

mediawiki mediawiki 1.22.4

mediawiki mediawiki 1.22.3

mediawiki mediawiki 1.21.10

mediawiki mediawiki 1.21.2

mediawiki mediawiki 1.21.9

mediawiki mediawiki 1.19.11

mediawiki mediawiki 1.20.6

mediawiki mediawiki 1.20.7

mediawiki mediawiki 1.19.3

mediawiki mediawiki 1.19.4

mediawiki mediawiki 1.22.6

mediawiki mediawiki 1.22.5

mediawiki mediawiki 1.23.0

mediawiki mediawiki 1.23.1

Vendor Advisories

Debian Bug report logs - #758510 mediawiki: 11918 fixes security vulnerabilities (CVE-2014-5241 CVE-2014-5243) Package: src:mediawiki; Maintainer for src:mediawiki is Kunal Mehta <legoktm@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 18 Aug 2014 10:33:02 UTC Severity: serious Tags: f ...