CVE-2015-2932
CVE-2015-2932
Incomplete blacklist vulnerability in MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to inject arbitrary web script or HTML via an animated href XLink element.
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://lists.wikimedia.org/pipermail/mediawiki-announce/2015-March/000175.htmlhttps://phabricator.wikimedia.org/T86711https://security.gentoo.org/glsa/201510-05http://www.mandriva.com/security/advisories?name=MDVSA-2015:200http://www.openwall.com/lists/oss-security/2015/04/01/1http://www.openwall.com/lists/oss-security/2015/04/07/3http://www.securityfocus.com/bid/73477