← back
CVE-2017-0372

Parameters injection in SyntaxHighlight results in multiple vulnerabilities

23Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 12%
from disclosure to weapon0 days
Published on NVDApr 13
metasploitApr 6
exploitation probability
12%top 4% of all CVEs
observed exploitation
nono source reports it
Parameters injection in the SyntaxHighlight extension of Mediawiki before 1.23.16, 1.27.3 and 1.28.2 might result in multiple vulnerabilities.