MediaWiki Versions Prior to 1.16.3 Multiple Remote Vulnerabilities
22 Jun. 2012
Summary
MediaWiki is prone to multiple remote vulnerabilities, including: 1. A cross-site scripting vulnerability, 2. An HTML-injection vulnerability, 3. An unauthorized-access vulnerability
Vulnerable Systems:
* MediaWiki MediaWiki 1.16.3 and prior
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the website, steal cookie-based authentication credentials, and perform remote imports from certain sources.
Versions prior to MediaWiki 1.16.3 are vulnerable.
Vendor Status:
Vendor as issued an update for this vulnerablity.