CVE-2019-12471
10.07.2019, 16:15
Wikimedia MediaWiki 1.30.0 through 1.32.1 has XSS. Loading user JavaScript from a non-existent account allows anyone to create the account, and perform XSS on users loading that script. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
Vendor | Product | Version |
---|---|---|
mediawiki | mediawiki | 1.30.0 ≤ 𝑥 < 1.30.2 |
mediawiki | mediawiki | 1.31.0 ≤ 𝑥 < 1.31.2 |
mediawiki | mediawiki | 1.32.0 ≤ 𝑥 < 1.32.2 |
debian | debian_linux | 9.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
mediawiki |
|
References