CVE-2013-4303
includes/libs/IEUrlExtension.php in the MediaWiki API in MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 does not properly detect extensions when there are an even number of "." (period) characters in a string, which…
Does this matter?
Lower severity and a low EPSS score (1.53%). Track it; it rarely justifies an emergency change on its own.
Description
includes/libs/IEUrlExtension.php in the MediaWiki API in MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 does not properly detect extensions when there are an even number of "." (period) characters in a string, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the siprop parameter in a query action to wiki/api.php.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.53% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- mediawiki/mediawiki
- Source
- secalert@redhat.com
References
- http://lists.wikimedia.org/pipermail/mediawiki-announce/2013-September/000133.htmlMailing List, Patch, Vendor Advisory
- http://seclists.org/oss-sec/2013/q3/553Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/62194Third Party Advisory, VDB Entry
- https://bugzilla.wikimedia.org/show_bug.cgi?id=52746Exploit, Issue Tracking, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/86897Third Party Advisory, VDB Entry
- http://lists.wikimedia.org/pipermail/mediawiki-announce/2013-September/000133.htmlMailing List, Patch, Vendor Advisory
- http://seclists.org/oss-sec/2013/q3/553Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/62194Third Party Advisory, VDB Entry
- https://bugzilla.wikimedia.org/show_bug.cgi?id=52746Exploit, Issue Tracking, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/86897Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.