MEDIUM
Incomplete blacklist vulnerability in Sanitizer::checkCss in MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 allows remote attackers to conduct cross-site scripting (XSS) attacks via a \b (backspace) character in CSS
Published Dec 13, 2013
4.3
MEDIUMCVSS 2.0
EPSS 1.35%
Description
Incomplete blacklist vulnerability in Sanitizer::checkCss in MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 allows remote attackers to conduct cross-site scripting (XSS) attacks via a \b (backspace) character in CSS.
Affected products
No data.
Configuration 1
OR
- ≤ 1.19.8
- 1.19
- 1.19
- 1.19
- 1.19.0
- 1.19.1
- 1.19.2
- 1.19.3
- 1.19.4
- 1.19.5
- 1.19.6
- 1.19.7
Configuration 2
OR
- 1.20
- 1.20.1
- 1.20.2
- 1.20.3
- 1.20.4
- 1.20.5
- 1.20.6
- 1.20.7
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (7)
- http://lists.fedoraproject.org/pipermail/package-announce/2013-December/122998.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2013-December/123011.html vendor-advisoryx_refsource_FEDORA
- http://lists.wikimedia.org/pipermail/mediawiki-announce/2013-November/000135.html mailing-listx_refsource_MLIST
- http://secunia.com/advisories/57472 third-party-advisoryx_refsource_SECUNIA
- http://www.debian.org/security/2014/dsa-2891 vendor-advisoryx_refsource_DEBIAN
- http://www.securityfocus.com/bid/63760 vdb-entryx_refsource_BID
- https://bugzilla.wikimedia.org/show_bug.cgi?id=55332 x_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| http://lists.fedoraproject.org/pipermail/package-announce/2013-December/122998.html | vendor-advisoryx_refsource_FEDORA | |
| http://lists.fedoraproject.org/pipermail/package-announce/2013-December/123011.html | vendor-advisoryx_refsource_FEDORA | |
| http://lists.wikimedia.org/pipermail/mediawiki-announce/2013-November/000135.html | mailing-listx_refsource_MLIST | |
| http://secunia.com/advisories/57472 | third-party-advisoryx_refsource_SECUNIA | |
| http://www.debian.org/security/2014/dsa-2891 | vendor-advisoryx_refsource_DEBIAN | |
| http://www.securityfocus.com/bid/63760 | vdb-entryx_refsource_BID | |
| https://bugzilla.wikimedia.org/show_bug.cgi?id=55332 | x_refsource_CONFIRM |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Dec 13, 2013
Updated Aug 6, 2024
Reserved Jun 12, 2013
Link CVE-2013-4567
CISA Vulnrichment
Updated n/a