LWN.net Logo

mediawiki-extensions: cross-site scripting

Package(s):mediawiki-extensions CVE #(s):
Created:December 31, 2012 Updated:January 8, 2013
Description: From the Debian advisory:

Thorsten Glaser discovered that the RSSReader extension for mediawiki, a website engine for collaborative work, does not properly escape tags in feeds. This could allow a malicious feed to inject JavaScript into the mediawiki pages.

Alerts:
Debian DSA-2596-1 2012-12-30

(Log in to post comments)

mediawiki-extensions: cross-site scripting

Posted Jan 8, 2013 19:01 UTC (Tue) by mirabilos (subscriber, #84359) [Link]

This is CVE-2012-6453 now.

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds