CVE Vulnerabilities

CVE-2013-4568

Published: Dec 13, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Incomplete blacklist vulnerability in Sanitizer::checkCss in MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 allows remote attackers to conduct cross-site scripting (XSS) attacks via certain non-ASCII characters in CSS, as demonstrated using variations of expression containing (1) full width characters or (2) IPA extensions, which are converted and rendered by Internet Explorer.

Affected Software

NameVendorStart VersionEnd Version
MediawikiMediawiki1.20 (including)1.20 (including)
MediawikiMediawiki1.20.1 (including)1.20.1 (including)
MediawikiMediawiki1.20.2 (including)1.20.2 (including)
MediawikiMediawiki1.20.3 (including)1.20.3 (including)
MediawikiMediawiki1.20.4 (including)1.20.4 (including)
MediawikiMediawiki1.20.5 (including)1.20.5 (including)
MediawikiMediawiki1.20.6 (including)1.20.6 (including)
MediawikiMediawiki1.20.7 (including)1.20.7 (including)
MediawikiUbuntulucid*
MediawikiUbuntuprecise*
MediawikiUbuntuquantal*
MediawikiUbunturaring*
MediawikiUbuntusaucy*
MediawikiUbuntuupstream*

References