CVE-2014-2853

EPSS 0.37%

Cross-site scripting vulnerability in includes/actions/InfoAction.php

Published: 5/17/2022Modified: 12/2/2024
Also known as:GHSA-6h86-9r5g-f2h5

Description

Cross-site scripting (XSS) vulnerability in includes/actions/InfoAction.php in MediaWiki before 1.21.9 and 1.22.x before 1.22.6 allows remote attackers to inject arbitrary web script or HTML via the sort key in an info action.

Affected packages (1)

References (11)