|
|
| |
|
| |
mediawiki-extensions: cross-site scripting
| Package(s): | mediawiki-extensions |
CVE #(s): | |
| Created: | December 31, 2012 |
Updated: | January 8, 2013 |
| Description: |
From the Debian advisory:
Thorsten Glaser discovered that the RSSReader extension for mediawiki, a
website engine for collaborative work, does not properly escape tags in
feeds. This could allow a malicious feed to inject JavaScript into the
mediawiki pages. |
| Alerts: |
|
( Log in to post comments)
|
|
|