CVE-2015-2935 Information
Feb 14, 2021
cve
Description
MediaWiki before 1.19.24 1.2x before 1.23.9 and 1.24.x before 1.24.2 allows remote attackers to bypass the SVG filtering and obtain sensitive user information via a mixed case @import in a style element in an SVG file as demonstrated by @imporT.\
Reference
http://www.mandriva.com/security/advisories?name=MDVSA-2015:200 http://www.openwall.com/lists/oss-security/2015/04/01/1 http://www.openwall.com/lists/oss-security/2015/04/07/3 http://www.securityfocus.com/bid/73477 https://lists.wikimedia.org/pipermail/mediawiki-announce/2015-March/000175.html https://phabricator.wikimedia.org/T85349 https://security.gentoo.org/glsa/201510-05
Share on: