Back to search
CVE-2014-3966
Published: Jun 6, 2014
Modified: Aug 6, 2024
PUBLISHED
Description
Cross-site scripting (XSS) vulnerability in Special:PasswordReset in MediaWiki before 1.19.16, 1.21.x before 1.21.10, and 1.22.x before 1.22.7, when wgRawHtml is enabled, allows remote attackers to inject arbitrary web script or HTML via an invalid username.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
58896
third-party-advisory
x_refsource_SECUNIA
1030364
vdb-entry
x_refsource_SECTRACK
https://bugzilla.wikimedia.org/show_bug.cgi?id=65501
x_refsource_CONFIRM
[MediaWiki-announce] 20140529 MediaWiki Security and Maintenance Releases: 1.19.16, 1.21.10 and 1.22.7
mailing-list
x_refsource_MLIST
DSA-2957
vendor-advisory
x_refsource_DEBIAN
67787
vdb-entry
x_refsource_BID
58834
third-party-advisory
x_refsource_SECUNIA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now