Vulnerability Name:

CVE-2013-4568 (CCN-88937)

Assigned:2013-11-14
Published:2013-11-14
Updated:2016-12-31
Summary:Incomplete blacklist vulnerability in Sanitizer::checkCss in MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 allows remote attackers to conduct cross-site scripting (XSS) attacks via certain non-ASCII characters in CSS, as demonstrated using variations of "expression" containing (1) full width characters or (2) IPA extensions, which are converted and rendered by Internet Explorer.
Per: http://cwe.mitre.org/data/definitions/184.html

"CWE-184: Incomplete Blacklist"
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-Other
Vulnerability Consequences:Cross-Site Scripting
References:Source: MITRE
Type: CNA
CVE-2013-4568

Source: FEDORA
Type: UNKNOWN
FEDORA-2013-21874

Source: FEDORA
Type: UNKNOWN
FEDORA-2013-21856

Source: CCN
Type: MediaWiki Mailing List, Thu Nov 14 21:59:24 UTC 2013
MediaWiki Security Release: 1.21.3, 1.20.8 and 1.19.9

Source: MLIST
Type: UNKNOWN
[MediaWiki-announce] 20131114 MediaWiki Security Release: 1.21.3, 1.20.8 and 1.19.9

Source: CCN
Type: SA55743
MediaWiki Session Cookies Disclosure Security Issue and Script Insertion Vulnerability

Source: SECUNIA
Type: UNKNOWN
57472

Source: DEBIAN
Type: UNKNOWN
DSA-2891

Source: CCN
Type: MediaWiki Web site
MediaWiki

Source: BID
Type: UNKNOWN
63761

Source: CCN
Type: BID-63761
Mediawiki CSS Tags CVE-2013-4568 HTML Injection Vulnerability

Source: CCN
Type: Red Hat Bugzilla Bug 1030987
(CVE-2013-4567, CVE-2013-4568, CVE-2013-4572) CVE-2013-4567 CVE-2013-4568 CVE-2013-4572 mediawiki: security releases 1.21.3, 1.20.8, and 1.19.9

Source: MISC
Type: UNKNOWN
https://bugzilla.wikimedia.org/attachment.cgi?id=13452&action=diff

Source: CONFIRM
Type: UNKNOWN
https://bugzilla.wikimedia.org/show_bug.cgi?id=55332

Source: XF
Type: UNKNOWN
parser-cve20134568-xss(88937)

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2013-4568

Vulnerable Configuration:Configuration 1:
  • cpe:/a:mediawiki:mediawiki:1.20:*:*:*:*:*:*:*
  • OR cpe:/a:mediawiki:mediawiki:1.20.1:*:*:*:*:*:*:*
  • OR cpe:/a:mediawiki:mediawiki:1.20.2:*:*:*:*:*:*:*
  • OR cpe:/a:mediawiki:mediawiki:1.20.3:*:*:*:*:*:*:*
  • OR cpe:/a:mediawiki:mediawiki:1.20.4:*:*:*:*:*:*:*
  • OR cpe:/a:mediawiki:mediawiki:1.20.5:*:*:*:*:*:*:*
  • OR cpe:/a:mediawiki:mediawiki:1.20.6:*:*:*:*:*:*:*
  • OR cpe:/a:mediawiki:mediawiki:1.20.7:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/a:mediawiki:mediawiki:1.21:*:*:*:*:*:*:*
  • OR cpe:/a:mediawiki:mediawiki:1.21.1:*:*:*:*:*:*:*
  • OR cpe:/a:mediawiki:mediawiki:1.21.2:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/a:mediawiki:mediawiki:1.19:*:*:*:*:*:*:*
  • OR cpe:/a:mediawiki:mediawiki:1.19:beta_1:*:*:*:*:*:*
  • OR cpe:/a:mediawiki:mediawiki:1.19:beta_2:*:*:*:*:*:*
  • OR cpe:/a:mediawiki:mediawiki:1.19.0:*:*:*:*:*:*:*
  • OR cpe:/a:mediawiki:mediawiki:1.19.1:*:*:*:*:*:*:*
  • OR cpe:/a:mediawiki:mediawiki:1.19.2:*:*:*:*:*:*:*
  • OR cpe:/a:mediawiki:mediawiki:1.19.3:*:*:*:*:*:*:*
  • OR cpe:/a:mediawiki:mediawiki:1.19.4:*:*:*:*:*:*:*
  • OR cpe:/a:mediawiki:mediawiki:1.19.5:*:*:*:*:*:*:*
  • OR cpe:/a:mediawiki:mediawiki:1.19.6:*:*:*:*:*:*:*
  • OR cpe:/a:mediawiki:mediawiki:1.19.7:*:*:*:*:*:*:*
  • OR cpe:/a:mediawiki:mediawiki:*:*:*:*:*:*:*:* (Version <= 1.19.8)

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:29092
    P
    DSA-2891-3 -- mediawiki, mediawiki-extensions -- security update
    2015-08-17
    oval:org.mitre.oval:def:29025
    P
    DSA-2891-2 -- mediawiki, mediawiki-extensions -- security update
    2015-08-17
    oval:org.mitre.oval:def:24466
    P
    DSA-2891-1 mediawiki - security update
    2014-06-23
    oval:com.ubuntu.precise:def:20134568000
    V
    CVE-2013-4568 on Ubuntu 12.04 LTS (precise) - medium.
    2013-12-13
    oval:com.ubuntu.trusty:def:20134568000
    V
    CVE-2013-4568 on Ubuntu 14.04 LTS (trusty) - medium.
    2013-12-13
    BACK
    mediawiki mediawiki 1.20
    mediawiki mediawiki 1.20.1
    mediawiki mediawiki 1.20.2
    mediawiki mediawiki 1.20.3
    mediawiki mediawiki 1.20.4
    mediawiki mediawiki 1.20.5
    mediawiki mediawiki 1.20.6
    mediawiki mediawiki 1.20.7
    mediawiki mediawiki 1.21
    mediawiki mediawiki 1.21.1
    mediawiki mediawiki 1.21.2
    mediawiki mediawiki 1.19
    mediawiki mediawiki 1.19 beta_1
    mediawiki mediawiki 1.19 beta_2
    mediawiki mediawiki 1.19.0
    mediawiki mediawiki 1.19.1
    mediawiki mediawiki 1.19.2
    mediawiki mediawiki 1.19.3
    mediawiki mediawiki 1.19.4
    mediawiki mediawiki 1.19.5
    mediawiki mediawiki 1.19.6
    mediawiki mediawiki 1.19.7
    mediawiki mediawiki *