CVE Vulnerabilities

CVE-2013-4568

Published: Dec 13, 2013 | Modified: Dec 31, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Incomplete blacklist vulnerability in Sanitizer::checkCss in MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 allows remote attackers to conduct cross-site scripting (XSS) attacks via certain non-ASCII characters in CSS, as demonstrated using variations of expression containing (1) full width characters or (2) IPA extensions, which are converted and rendered by Internet Explorer.

Affected Software

Name Vendor Start Version End Version
Mediawiki Mediawiki 1.20.5 1.20.5
Mediawiki Mediawiki 1.20.1 1.20.1
Mediawiki Mediawiki 1.20.4 1.20.4
Mediawiki Mediawiki 1.20.2 1.20.2
Mediawiki Mediawiki 1.20.3 1.20.3
Mediawiki Mediawiki 1.20.6 1.20.6
Mediawiki Mediawiki 1.20 1.20
Mediawiki Mediawiki 1.20.7 1.20.7

References