Back to search
CVE-2017-0371
Published: Feb 18, 2022
Modified: Aug 5, 2024
PUBLISHED
Description
MediaWiki before 1.23.16, 1.24.x through 1.27.x before 1.27.2, and 1.28.x before 1.28.1 allows remote attackers to discover the IP addresses of Wiki visitors via a style="background-image: attr(title url);" attack within a DIV element that has an attacker-controlled URL in the title attribute.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://phabricator.wikimedia.org/T140591
x_refsource_MISC
https://phabricator.wikimedia.org/T68404
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now