Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7955-v6mw-3hh5

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to bypass the SVG filtering and obtain sensitive user information via a mixed case @import in a style element in an SVG file, as demonstrated by "@imporT."

MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to bypass the SVG filtering and obtain sensitive user information via a mixed case @import in a style element in an SVG file, as demonstrated by "@imporT."

EPSS

Процентиль: 83%
0.02434
Низкий

Дефекты

CWE-200

Связанные уязвимости

ubuntu
больше 11 лет назад

MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to bypass the SVG filtering and obtain sensitive user information via a mixed case @import in a style element in an SVG file, as demonstrated by "@imporT."

nvd
больше 11 лет назад

MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to bypass the SVG filtering and obtain sensitive user information via a mixed case @import in a style element in an SVG file, as demonstrated by "@imporT."

debian
больше 11 лет назад

MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 ...

EPSS

Процентиль: 83%
0.02434
Низкий

Дефекты

CWE-200