Vulnerabilities
Vulnerable Software
Mediawiki:  >> Mediawiki  >> 1.34  Security Vulnerabilities
In the GlobalBlocking extension before 2020-03-10 for MediaWiki through 1.34.0, an issue related to IP range evaluation resulted in blocked users re-gaining escalated privileges. This is related to the case in which an IP address is contained in two ranges, one of which is locally disabled.
CVSS Score
9.8
EPSS Score
0.003
Published
2020-03-12
The MinervaNeue Skin in MediaWiki from 2019-11-05 to 2019-12-13 (1.35 and/or 1.34) mishandles certain HTML attributes, as demonstrated by IMG onmouseover= (impact is XSS) and IMG src=http (impact is disclosing the client's IP address). This can occur within a talk page topical header that is viewed within a mobile (MobileFrontend) context.
CVSS Score
6.1
EPSS Score
0.004
Published
2019-12-19


Contact Us

Shodan ® - All rights reserved