← Back

CVE-2014-7295

nvd nist
Published: Oct 7, 2014Modified: May 6, 2026

JSON object

Loading...
3.5
Vector
AV:N/AC:M/Au:S/C:N/I:P/A:N
Exploitability: 6.8 / Impact: 2.9
Source: NVD

Description

The (1) Special:Preferences and (2) Special:UserLogin pages in MediaWiki before 1.19.20, 1.22.x before 1.22.12 and 1.23.x before 1.23.5 allows remote authenticated users to conduct cross-site scripting (XSS) attacks or have unspecified other impact via crafted CSS, as demonstrated by modifying MediaWiki:Common.css.

Affected (40)

Products: Mediawiki: Mediawiki
1 product
Mediawiki
Configuration A
40 vulnerable
Vulnerable SoftwareAffected Versions
Mediawiki
Up to 1.19.19
Version 1.19.0
Version 1.19.10
Version 1.19.11
Version 1.19.12
Version 1.19.13
Version 1.19.14
Version 1.19.15
Version 1.19.16
Version 1.19.17
Version 1.19.18
Version 1.19.1
Version 1.19.2
Version 1.19.3
Version 1.19.4
Version 1.19.5
Version 1.19.6
Version 1.19.7
Version 1.19.8
Version 1.19.9
Version 1.19
Version 1.19 beta_1
Version 1.19 beta_2
Version 1.22.0
Version 1.22.10
Version 1.22.11
Version 1.22.1
Version 1.22.2
Version 1.22.3
Version 1.22.4
Version 1.22.5
Version 1.22.6
Version 1.22.7
Version 1.22.8
Version 1.22.9
Version 1.23.0
Version 1.23.1
Version 1.23.2
Version 1.23.3
Version 1.23.4

References (12)

Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch

Timeline

No history available yet.