CVE-2017-0371 Information
Jun 07, 2022
cve
Description
MediaWiki before 1.23.16 1.24.x through 1.27.x before 1.27.2 and 1.28.x before 1.28.1 allows remote attackers to discover the IP addresses of Wiki visitors via a style=ackground-image: attr(title url);\ attack within a DIV element that has an attacker-controlled URL in the title attribute.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Reference
https://phabricator.wikimedia.org/T68404
https://phabricator.wikimedia.org/T140591
MediaWiki
before
1.23.16
1.24.x
through
1.27.x
before
1.27.2
and
1.28.x
before
1.28.1
allows
remote
attackers
to
discover
the
IP
addresses
of
Wiki
visitors
via
a
style=ackground-image:
attr(title
url);
attack
within
a
DIV
element
that
has
an
attacker-controlled
URL
in
the
title
attribute.
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
7.5
Share on: