CVE-2014-5243

critical

Description

MediaWiki before 1.19.18, 1.20.x through 1.22.x before 1.22.9, and 1.23.x before 1.23.2 does not enforce an IFRAME protection mechanism for transcluded pages, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site.

References

https://lists.wikimedia.org/pipermail/mediawiki-announce/2014-July/000157.html

http://www.mandriva.com/security/advisories?name=MDVSA-2014:153

http://www.debian.org/security/2014/dsa-3011

http://secunia.com/advisories/59738

http://openwall.com/lists/oss-security/2014/08/14/5

http://advisories.mageia.org/MGASA-2014-0309.html

Details

Source: Mitre, NVD

Published: 2014-08-22

Updated: 2017-01-07

Risk Information

CVSS v2

Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical