Improper Input Validation Affecting mediawiki package, versions <1:1.15.2-1


Severity

Recommended
low

Based on Debian security rating.

Threat Intelligence

EPSS
0.4% (74th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Improper Input Validation vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-DEBIAN10-MEDIAWIKI-370544
  • published31 Mar 2010
  • disclosed31 Mar 2010

Introduced: 31 Mar 2010

CVE-2010-1189  (opens in a new tab)
CWE-20  (opens in a new tab)

How to fix?

Upgrade Debian:10 mediawiki to version 1:1.15.2-1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream mediawiki package and not the mediawiki package as distributed by Debian. See How to fix? for Debian:10 relevant fixed versions and status.

MediaWiki before 1.15.2 does not prevent wiki editors from linking to images from other web sites in wiki pages, which allows editors to obtain IP addresses and other information of wiki users by adding a link to an image on an attacker-controlled web site, aka "CSS validation issue."

CVSS Scores

version 3.1