MediaWiki before 1.15.2 does not prevent wiki editors from linking...
Vulnerability Description
MediaWiki before 1.15.2 does not prevent wiki editors from linking to images from other web sites in wiki pages, which allows editors to obtain IP addresses and other information of wiki users by adding a link to an image on an attacker-controlled web site, aka "CSS validation issue."
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2010-1189
Credits & Attribution
No credits recorded in the NVD database.
References
- http://secunia.com/advisories/39656
- http://www.debian.org/security/2010/dsa-2022
- http://lists.wikimedia.org/pipermail/mediawiki-announce/2010-March/000088.html
- http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00006.html
- http://www.vupen.com/english/advisories/2010/0685
- http://secunia.com/advisories/39022
- http://www.vupen.com/english/advisories/2010/1001
More from mediawiki
View All →Affected Vendor
mediawiki
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.