Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3hc7-mwwv-ff3c

Опубликовано: 20 фев. 2022
Источник: github
Github: Не прошло ревью

Описание

MediaWiki before 1.23.16, 1.24.x through 1.27.x before 1.27.2, and 1.28.x before 1.28.1 allows remote attackers to discover the IP addresses of Wiki visitors via a style="background-image: attr(title url);" attack within a DIV element that has an attacker-controlled URL in the title attribute.

MediaWiki before 1.23.16, 1.24.x through 1.27.x before 1.27.2, and 1.28.x before 1.28.1 allows remote attackers to discover the IP addresses of Wiki visitors via a style="background-image: attr(title url);" attack within a DIV element that has an attacker-controlled URL in the title attribute.

EPSS

Процентиль: 44%
0.00212
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 4 года назад

MediaWiki before 1.23.16, 1.24.x through 1.27.x before 1.27.2, and 1.28.x before 1.28.1 allows remote attackers to discover the IP addresses of Wiki visitors via a style="background-image: attr(title url);" attack within a DIV element that has an attacker-controlled URL in the title attribute.

CVSS3: 7.5
redhat
почти 4 года назад

MediaWiki before 1.23.16, 1.24.x through 1.27.x before 1.27.2, and 1.28.x before 1.28.1 allows remote attackers to discover the IP addresses of Wiki visitors via a style="background-image: attr(title url);" attack within a DIV element that has an attacker-controlled URL in the title attribute.

CVSS3: 7.5
nvd
почти 4 года назад

MediaWiki before 1.23.16, 1.24.x through 1.27.x before 1.27.2, and 1.28.x before 1.28.1 allows remote attackers to discover the IP addresses of Wiki visitors via a style="background-image: attr(title url);" attack within a DIV element that has an attacker-controlled URL in the title attribute.

CVSS3: 7.5
debian
почти 4 года назад

MediaWiki before 1.23.16, 1.24.x through 1.27.x before 1.27.2, and 1.2 ...

EPSS

Процентиль: 44%
0.00212
Низкий