CVE-2012-1582
EPSS 0.64%發布日:2012/9/9修改日:2026/4/28
描述
Cross-site scripting (XSS) vulnerability in the wikitext parser in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 allows remote attackers to inject arbitrary web script or HTML via a crafted page with "forged strip item markers," as demonstrated using the CharInsert extension.
受影響套件(1)
- Debian/mediawikifrom 0, < 1:1.15.5-9