CVE-2013-6452
EPSS 0.32%Published: 5/12/2014Modified: 4/28/2026
Also known as:DEBIAN-CVE-2013-6452
Description
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to inject arbitrary web script or HTML via crafted XSL in an SVG file.
Affected packages (1)
- Debian/mediawikifrom 0, < 1:1.19.10+dfsg-1