CVE-2014-2853

EPSS 0.37%

Cross-site scripting vulnerability in includes/actions/InfoAction.php

發布日:2022/5/17修改日:2024/12/2

描述

Cross-site scripting (XSS) vulnerability in includes/actions/InfoAction.php in MediaWiki before 1.21.9 and 1.22.x before 1.22.6 allows remote attackers to inject arbitrary web script or HTML via the sort key in an info action.

受影響套件(1)

參考連結(11)