Vulnerability Name: CVE-2013-4568 (CCN-88937) Assigned: 2013-11-14 Published: 2013-11-14 Updated: 2016-12-31 Summary: Incomplete blacklist vulnerability in Sanitizer::checkCss in MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 allows remote attackers to conduct cross-site scripting (XSS) attacks via certain non-ASCII characters in CSS, as demonstrated using variations of "expression" containing (1) full width characters or (2) IPA extensions, which are converted and rendered by Internet Explorer. Per: http://cwe.mitre.org/data/definitions/184.html "CWE-184: Incomplete Blacklist" CVSS v3 Severity: 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): NoneIntegrity (I): LowAvailibility (A): None
CVSS v2 Severity: 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N )3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): MediumAuthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): PartialAvailibility (A): None
4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N )3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): MediumAthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): PartialAvailibility (A): None
Vulnerability Type: CWE-Other Vulnerability Consequences: Cross-Site Scripting References: Source: MITRE Type: CNACVE-2013-4568 Source: FEDORA Type: UNKNOWNFEDORA-2013-21874 Source: FEDORA Type: UNKNOWNFEDORA-2013-21856 Source: CCN Type: MediaWiki Mailing List, Thu Nov 14 21:59:24 UTC 2013MediaWiki Security Release: 1.21.3, 1.20.8 and 1.19.9 Source: MLIST Type: UNKNOWN[MediaWiki-announce] 20131114 MediaWiki Security Release: 1.21.3, 1.20.8 and 1.19.9 Source: CCN Type: SA55743MediaWiki Session Cookies Disclosure Security Issue and Script Insertion Vulnerability Source: SECUNIA Type: UNKNOWN57472 Source: DEBIAN Type: UNKNOWNDSA-2891 Source: CCN Type: MediaWiki Web siteMediaWiki Source: BID Type: UNKNOWN63761 Source: CCN Type: BID-63761Mediawiki CSS Tags CVE-2013-4568 HTML Injection Vulnerability Source: CCN Type: Red Hat Bugzilla Bug 1030987(CVE-2013-4567, CVE-2013-4568, CVE-2013-4572) CVE-2013-4567 CVE-2013-4568 CVE-2013-4572 mediawiki: security releases 1.21.3, 1.20.8, and 1.19.9 Source: MISC Type: UNKNOWNhttps://bugzilla.wikimedia.org/attachment.cgi?id=13452&action=diff Source: CONFIRM Type: UNKNOWNhttps://bugzilla.wikimedia.org/show_bug.cgi?id=55332 Source: XF Type: UNKNOWNparser-cve20134568-xss(88937) Source: CCN Type: WhiteSource Vulnerability DatabaseCVE-2013-4568 Vulnerable Configuration: Configuration 1 :cpe:/a:mediawiki:mediawiki:1.20:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.20.1:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.20.2:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.20.3:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.20.4:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.20.5:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.20.6:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.20.7:*:*:*:*:*:*:* Configuration 2 :cpe:/a:mediawiki:mediawiki:1.21:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.21.1:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.21.2:*:*:*:*:*:*:* Configuration 3 :cpe:/a:mediawiki:mediawiki:1.19:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.19:beta_1:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.19:beta_2:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.19.0:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.19.1:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.19.2:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.19.3:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.19.4:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.19.5:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.19.6:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.19.7:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:*:*:*:*:*:*:*:* (Version <= 1.19.8) Denotes that component is vulnerable Oval Definitions BACK
mediawiki mediawiki 1.20
mediawiki mediawiki 1.20.1
mediawiki mediawiki 1.20.2
mediawiki mediawiki 1.20.3
mediawiki mediawiki 1.20.4
mediawiki mediawiki 1.20.5
mediawiki mediawiki 1.20.6
mediawiki mediawiki 1.20.7
mediawiki mediawiki 1.21
mediawiki mediawiki 1.21.1
mediawiki mediawiki 1.21.2
mediawiki mediawiki 1.19
mediawiki mediawiki 1.19 beta_1
mediawiki mediawiki 1.19 beta_2
mediawiki mediawiki 1.19.0
mediawiki mediawiki 1.19.1
mediawiki mediawiki 1.19.2
mediawiki mediawiki 1.19.3
mediawiki mediawiki 1.19.4
mediawiki mediawiki 1.19.5
mediawiki mediawiki 1.19.6
mediawiki mediawiki 1.19.7
mediawiki mediawiki *