CVE-2014-9481
27.01.2020, 16:15
The Scribunto extension for MediaWiki allows remote attackers to obtain the rollback token and possibly other sensitive information via a crafted module, related to unstripping special page HTML.Enginsight
Vendor | Product | Version |
---|---|---|
mediawiki | mediawiki | 𝑥 < 1.19.23 |
mediawiki | mediawiki | 1.19.24 ≤ 𝑥 < 1.22.15 |
mediawiki | mediawiki | 1.23.0 ≤ 𝑥 < 1.23.8 |
mediawiki | mediawiki | 1.23.9 ≤ 𝑥 < 1.24.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References