MediaWiki Widgets XSS Vulnerability (CVE-2015-6737)
MediaWiki Widgets XSS Vulnerability (CVE-2015-6737)
Release date:
Updated on: 2015-09-02
Affected Systems:
MediaWiki <1.25.2
MediaWiki <1.24.3
MediaWiki <1.23.10
Description:
CVE (CAN) ID: CVE-2015-6737
MediaWiki is a famous wiki program running in the PHP + MySQL environment.
MediaWiki's Widgets extension has multiple cross-site scripting vulnerabilities, allowing remote attackers to inject Web scripts or HTML content through base64 encoding.
<* Source: MediaWiki
*>
Suggestion:
Vendor patch:
MediaWiki
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.openwall.com/lists/oss-security/2015/08/27/6
Https://lists.wikimedia.org/pipermail/mediawiki-announce/2015-August/000179.html
Http://lists.fedoraproject.org/pipermail/package-announce/2015-August/165193.html
Http://www.openwall.com/lists/oss-security/2015/08/12/6
This article permanently updates the link address: