MediaWiki < 1.19.19 / 1.22.11 / 1.23.4 SVG Upload and CSS XSS

medium Nessus Plugin ID 78063

Synopsis

The remote web server contains an application that is affected by a cross-site scripting vulnerability.

Description

According to its version number, the MediaWiki application running on the remote host is affected by an input validation error related to SVG file upload handling and CSS content filtering that can lead to cross-site scripting (XSS) attacks.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to MediaWiki version 1.19.19 / 1.22.11 / 1.23.4 or later.

See Also

http://www.nessus.org/u?30d6ff9d

https://www.mediawiki.org/wiki/Release_notes/1.19#MediaWiki_1.19.19

https://www.mediawiki.org/wiki/Release_notes/1.22#MediaWiki_1.22.11

https://www.mediawiki.org/wiki/Release_notes/1.23#MediaWiki_1.23.4

https://phabricator.wikimedia.org/T71008

Plugin Details

Severity: Medium

ID: 78063

File Name: mediawiki_1_23_4.nasl

Version: 1.7

Type: remote

Published: 10/6/2014

Updated: 4/11/2022

Configuration: Enable paranoid mode, Enable thorough checks

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.0

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Information

CPE: cpe:/a:mediawiki:mediawiki

Required KB Items: www/PHP, Settings/ParanoidReport, installed_sw/MediaWiki

Exploit Ease: No exploit is required

Patch Publication Date: 9/24/2014

Vulnerability Publication Date: 9/24/2014

Reference Information

CVE: CVE-2014-7199

BID: 70153

CWE: 20, 442, 629, 711, 712, 722, 725, 74, 750, 751, 79, 800, 801, 809, 811, 864, 900, 928, 931, 990