5
CVSSv2

CVE-2017-0370

Published: 13/04/2018 Updated: 14/05/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Mediawiki prior to 1.28.1 / 1.27.2 / 1.23.16 contains a flaw were Spam blacklist is ineffective on encoded URLs inside file inclusion syntax's link parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

mediawiki mediawiki

debian debian linux 7.0

Vendor Advisories

The spam blacklist in MediaWiki before 1281 could be bypassed by encoding URLs inside a file inclusion syntax's link parameter ...