Lucene search

K
kasperskyKaspersky LabKLA10545
HistoryApr 13, 2015 - 12:00 a.m.

KLA10545 Multiple vulnerabilities in MediaWiki and extensions

2015-04-1300:00:00
Kaspersky Lab
threats.kaspersky.com
22

CVSS2

7.1

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:N/I:N/A:C

AI Score

7.3

Confidence

High

EPSS

0.036

Percentile

91.7%

Multiple serious vulnerabilities have been found in MediaWiki. Malicious users can exploit these vulnerabilities to bypass security restrictions, inject arbitrary code, cause denial of service or obtain sensitive information.

Below is a complete list of vulnerabilities

  1. Unknown vulnerability can be exploited remotely via a specially designed SVG, PDF, password or entity manipuations;
  2. XSS vulnerability in CheckUser extension can be exploited remotely via a specially designed request;
  3. CSRF vulnerability in Scripunto extension can be exploited remotely via an unknown vectors;
  4. XSS vulnerability can be exploited remotely via a specially designed JS or string;
  5. Improper entities handle can be exploited remotely via a specially designed SVG file;
  6. Incomplete blacklist can be exploited remotely via a specially designed XLink or SVG.

Original advisories

MediaWiki notice

Related products

MediaWiki

CVE list

CVE-2015-2941 warning

CVE-2015-2942 high

CVE-2015-2932 warning

CVE-2015-2931 warning

CVE-2015-2938 warning

CVE-2015-2937 high

CVE-2015-2936 high

CVE-2015-2935 critical

CVE-2015-2939 warning

CVE-2015-2940 high

CVE-2015-2933 warning

CVE-2015-2934 warning

Solution

Update to the latest version.

Get MediaWiki

Impacts

  • OSI

Obtain sensitive information. Exploitation of vulnerabilities with this impact can lead to capturing by abuser information, critical for user or system.

  • DoS

Denial of service. Exploitation of vulnerabilities with this impact can lead to loss of system availability or critical functional fault.

  • CI

Code injection. Exploitation of vulnerabilities with this impact can lead to changes in target code.

  • SB

Security bypass. Exploitation of vulnerabilities with this impact can lead to performing actions restricted by current security settings.

Affected Products

  • MediaWiki versions earlier thanย 1.19.24MediaWiki 1.2x versions earlier thanย 1.23.9MediaWikiย 1.24.x versions earlier thanย 1.24.2

CVSS2

7.1

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:N/I:N/A:C

AI Score

7.3

Confidence

High

EPSS

0.036

Percentile

91.7%