Vulnerability Name: CVE-2015-8622 (CCN-110259) Assigned: 2015-12-23 Published: 2015-12-23 Updated: 2017-03-27 Summary: Cross-site scripting (XSS) vulnerability in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1, when is configured with a relative URL, allows remote authenticated users to inject arbitrary web script or HTML via wikitext, as demonstrated by a wikilink to a page named "javascript:alert('XSS!')." CVSS v3 Severity: 6.1 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N )5.4 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:U/RL:U/RC:R )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): RequiredScope: Scope (S): ChangedImpact Metrics: Confidentiality (C): LowIntegrity (I): LowAvailibility (A): None
6.1 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N )5.4 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:U/RL:U/RC:R )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): RequiredScope: Scope (S): ChangedImpact Metrics: Confidentiality (C): LowIntegrity (I): LowAvailibility (A): None
CVSS v2 Severity: 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): MediumAuthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): PartialAvailibility (A): None
5.5 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAthentication (Au): Single_InstanceImpact Metrics: Confidentiality (C): PartialIntegrity (I): PartialAvailibility (A): None
Vulnerability Type: CWE-79 Vulnerability Consequences: Cross-Site Scripting References: Source: MITRE Type: CNACVE-2015-8622 Source: CCN Type: oss-sec Mailing List, Wed, 23 Dec 2015 14:06:58 -0500 (EST)Re: CVE requests for MediaWiki 1.26.1, 1.25.4, 1.24.5 and 1.23.12 Source: MLIST Type: Mailing List, Patch, Third Party Advisory[oss-security] 20151221 CVE requests for MediaWiki 1.26.1, 1.25.4, 1.24.5 and 1.23.12 Source: MLIST Type: Mailing List, Patch, Third Party Advisory[oss-security] 20151223 Re: CVE requests for MediaWiki 1.26.1, 1.25.4, 1.24.5 and 1.23.12 Source: XF Type: UNKNOWNmediawiki-cve20158622-xss(110259) Source: MLIST Type: Patch, Release Notes, Vendor Advisory[MediaWiki-announce] 20151221 [MediaWiki-announce] Security Release: 1.26.1, 1.25.4, 1.24.5 and 1.23.12 Source: CONFIRM Type: Issue Tracking, Patch, Third Party Advisoryhttps://phabricator.wikimedia.org/T117899 Source: CCN Type: MediaWiki Web siteMediaWiki Source: CCN Type: WhiteSource Vulnerability DatabaseCVE-2015-8622 Vulnerable Configuration: Configuration 1 :cpe:/a:mediawiki:mediawiki:*:*:*:*:*:*:*:* (Version <= 1.23.11)OR cpe:/a:mediawiki:mediawiki:1.24.0:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.24.1:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.24.2:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.24.3:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.24.4:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.25.0:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.25.1:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.25.2:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.25.3:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.26.0:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:mediawiki:mediawiki:1.26.1:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.25.4:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.24.5:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.23.12:*:*:*:*:*:*:* Denotes that component is vulnerable Oval Definitions BACK
mediawiki mediawiki *
mediawiki mediawiki 1.24.0
mediawiki mediawiki 1.24.1
mediawiki mediawiki 1.24.2
mediawiki mediawiki 1.24.3
mediawiki mediawiki 1.24.4
mediawiki mediawiki 1.25.0
mediawiki mediawiki 1.25.1
mediawiki mediawiki 1.25.2
mediawiki mediawiki 1.25.3
mediawiki mediawiki 1.26.0
mediawiki mediawiki 1.26.1
mediawiki mediawiki 1.25.4
mediawiki mediawiki 1.24.5
mediawiki mediawiki 1.23.12