Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cqgp-cp8g-949g

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

MediaWiki before 1.15.2 does not prevent wiki editors from linking to images from other web sites in wiki pages, which allows editors to obtain IP addresses and other information of wiki users by adding a link to an image on an attacker-controlled web site, aka "CSS validation issue."

MediaWiki before 1.15.2 does not prevent wiki editors from linking to images from other web sites in wiki pages, which allows editors to obtain IP addresses and other information of wiki users by adding a link to an image on an attacker-controlled web site, aka "CSS validation issue."

EPSS

Процентиль: 59%
0.00381
Низкий

Дефекты

CWE-20

Связанные уязвимости

ubuntu
больше 15 лет назад

MediaWiki before 1.15.2 does not prevent wiki editors from linking to images from other web sites in wiki pages, which allows editors to obtain IP addresses and other information of wiki users by adding a link to an image on an attacker-controlled web site, aka "CSS validation issue."

redhat
почти 16 лет назад

MediaWiki before 1.15.2 does not prevent wiki editors from linking to images from other web sites in wiki pages, which allows editors to obtain IP addresses and other information of wiki users by adding a link to an image on an attacker-controlled web site, aka "CSS validation issue."

nvd
больше 15 лет назад

MediaWiki before 1.15.2 does not prevent wiki editors from linking to images from other web sites in wiki pages, which allows editors to obtain IP addresses and other information of wiki users by adding a link to an image on an attacker-controlled web site, aka "CSS validation issue."

debian
больше 15 лет назад

MediaWiki before 1.15.2 does not prevent wiki editors from linking to ...

EPSS

Процентиль: 59%
0.00381
Низкий

Дефекты

CWE-20