MediaWiki SemanticForms XSS Vulnerability (CVE-2015-6731)
MediaWiki SemanticForms XSS Vulnerability (CVE-2015-6731)
Release date:
Updated on: 2015-09-02
Affected Systems:
MediaWiki <1.25.2
MediaWiki <1.24.3
MediaWiki <1.23.10
Description:
CVE (CAN) ID: CVE-2015-6731
MediaWiki is a famous wiki program running in the PHP + MySQL environment.
Multiple cross-site scripting vulnerabilities exist in the SemanticForms extension of MediaWiki. Remote attackers can use the section _ *, template _ *, label _ *, new_template, target, and alt_form parameters, inject Web scripts or HTML in Special: CreateForm or Special: FormEdit.
<* Source: MediaWiki
*>
Suggestion:
Vendor patch:
MediaWiki
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://phabricator.wikimedia.org/T103391
This article permanently updates the link address: